omnifaces is vulnerable to Missing Authorization
59
Medium Risk
The SSE push transport exposed through <o:sse> accepts a connection whenever the presented channel ID exists in the application-wide registry, without checking that the caller's HTTP session owns it. Session- and view-scoped channel IDs can therefore be replayed from any HTTP session, or none, to receive pushed messages. Because these channel IDs can leak through logs, headers, links, and referrers, private messages intended for one session can be intercepted without authentication. The fix binds session- and view-scoped SSE channel IDs to their owning HTTP session and refuses connections that do not own the channel.
You are affected if you are using a version that falls within the vulnerable range and you use <o:sse> push with session or view scope.
omnifaces is vulnerable to Missing Authorization in versions 5.2.0 - 5.4.2.
Upgrade the org.omnifaces:omnifaces library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant