Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgg6-8x62-m9gf

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Certificate Validation in Apache CXF

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

Пакеты

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

>= 3.1.0, <= 3.1.10

3.1.11

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

<= 3.0.12

3.0.13

EPSS

Процентиль: 87%
0.03167
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.5
redhat
почти 9 лет назад

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

CVSS3: 5.3
nvd
почти 9 лет назад

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

EPSS

Процентиль: 87%
0.03167
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295