Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2379

Опубликовано: 07 июн. 2012
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss SOA Platform 5SecurityAffected
JBEWP 5 for RHEL 5aopallianceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5bsh2FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5google-guiceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3-annotationsFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3-entitymanagerFixedRHSA-2013:019624.01.2013

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=826534apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token

EPSS

Процентиль: 88%
0.03752
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

github
больше 3 лет назад

XML Signature/Encryption Not Validated in Apache CXF

EPSS

Процентиль: 88%
0.03752
Низкий

5.8 Medium

CVSS2

Уязвимость CVE-2012-2379