Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v45r-rj5x-hpg2

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Cleartext Transmission of Sensitive Information in Apache CXF

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

Пакеты

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

< 2.6.13

2.6.13

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.10

2.7.10

EPSS

Процентиль: 76%
0.00956
Низкий

Дефекты

CWE-319

Связанные уязвимости

redhat
почти 12 лет назад

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

nvd
больше 11 лет назад

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS

Процентиль: 76%
0.00956
Низкий

Дефекты

CWE-319