omnifaces is vulnerable to Missing Authorization
59
Medium Risk
The <o:socket> WebSocket handshake accepts any client presenting a channel ID that is registered in the application, without verifying that the calling HTTP session owns that channel. Session- and view-scoped channels can therefore be opened from unrelated sessions when the channel ID leaks through links, logs, referrers, or scripts. Messages pushed to a private channel can then be received without authentication, while application-scoped channels are unaffected. The fix binds session- and view-scoped channel IDs to their owning HTTP session and enforces ownership during the handshake.
You are affected if you are using a version that falls within the vulnerable range and you use <o:socket> push with session or view scope.
omnifaces is vulnerable to Missing Authorization in versions 2.3.0 - 2.7.32, 3.0.0 - 3.14.22, 4.0.0 - 4.7.11 and 5.0.0 - 5.4.1.
Upgrade the org.omnifaces:omnifaces library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant