Description

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

Severity (CVSS)

Base score8.1
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Provided byCISA-ADP

Weaknesses

  • CWE-367 — CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Affected products

VendorProductVersions
Apache Software FoundationApache CXF4.2.0 to <4.2.3; 4.0.0 to <4.1.8; 0 to <3.6.12

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 07 Aug 2026 07:02 UTC.