Uploaded image for project: 'WSS4J'
  1. WSS4J
  2. WSS-252

org.apache.ws.security.processor.UsernameTokenProcessor is not thread safe/prone to hacker attacks

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Won't Fix
    • 1.5.9
    • None
    • WSS4J Handlers
    • None
    • Any

    Description

      The UsernameTokenProcessorshould be thread safe, but it caches the UsernameToken (ut) and its ID (utId). This may allow a hacker to access the system with incorrect password if two threads happen to go through the code in parallel.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            marekcyzio Marek Cyzio
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: