Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf9f-32gh-h2w4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Authentication in Apache CXF

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

Ссылки

Пакеты

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

< 2.5.8

2.5.8

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.5

2.6.5

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

EPSS

Процентиль: 84%
0.02299
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

redhat
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

nvd
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

debian
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6 ...

EPSS

Процентиль: 84%
0.02299
Низкий

Дефекты

CWE-287