[ 
https://issues.apache.org/jira/browse/CXF-9240?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Colm O hEigeartaigh resolved CXF-9240.
--------------------------------------
    Resolution: Fixed

> OAuthJSONProvider.appendJsonPair() does not escape JSON string values — 
> output injection / malformed JSON in introspect & token responses
> -----------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CXF-9240
>                 URL: https://issues.apache.org/jira/browse/CXF-9240
>             Project: CXF
>          Issue Type: Bug
>          Components: JAX-RS Security
>    Affects Versions: 4.2.1
>         Environment: Apache CXF 4.2.1, Java 11+, OAuth2 AS endpoints 
> (introspect / token / error responses).
>            Reporter: Guanping Zhang
>            Assignee: Colm O hEigeartaigh
>            Priority: Minor
>             Fix For: 4.1.9, 4.2.4, 3.6.13
>
>
> OAuthJSONProvider.appendJsonPair() (approx. lines 206-217) wraps string 
> values in double quotes but performs no JSON escaping of the value. 
> Characters such as '"', '\' and control characters (newline, CR, tab, etc.) 
> are emitted verbatim, producing structurally broken JSON or allowing 
> injection of additional JSON content (CWE-74; violates RFC 8259 §7 string 
> escaping).
> Responses serialized through this method include:
> - /introspect (username, client_id, scope)
> - /token (scope and custom parameters)
> - error responses (error_description)
> If an attacker can influence a serialized value that is later reflected in a 
> response, the unescaped output can alter the JSON parsed by downstream 
> clients. Impact is downstream-parser-dependent; this is primarily an 
> output-encoding correctness defect with potential security impact.
> Suggested fix: apply proper JSON string escaping in appendJsonPair (escape 
> '"', '\' and control characters per RFC 8259 §7), or delegate serialization 
> to the existing JsonMapObjectReaderWriter, which handles escaping.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to