Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjpc-vf4f-82qg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Authentication in Apache CXF

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

Ссылки

Пакеты

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.4.5, < 2.4.8

2.4.8

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.5.1, < 2.5.3

2.5.3

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.1

2.6.1

EPSS

Процентиль: 89%
0.04238
Низкий

Дефекты

CWE-287

Связанные уязвимости

redhat
больше 13 лет назад

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

nvd
около 13 лет назад

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

EPSS

Процентиль: 89%
0.04238
Низкий

Дефекты

CWE-287