Vulnerabilities > Apache > CXF > 3.3.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-16 | CVE-2019-12423 | Insufficiently Protected Credentials vulnerability in multiple products Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. | 7.5 |