Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41000

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 3.7

Описание

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

A flaw was found in Spring Web Services. The security interceptor in the affected component did not properly integrate replay cache mechanisms. This vulnerability could allow a remote attacker to bypass replay protections for security tokens, such as UsernameToken nonces and SAML one-time-use elements. The consequence is a low integrity impact, where an attacker might be able to reuse tokens for unauthorized actions.

Отчет

Red Hat rates this vulnerability as Low impact with a CVSS score of 3.7, consistent with the upstream assessment. Attack Complexity is High (AC:H) because the attacker must first capture a valid SOAP message in transit and then replay it within the token acceptance window, which defaults to 300 seconds. Impact is limited to integrity (I:L), as a replayed message can only repeat an already-authorized operation with no effect on confidentiality or availability. Red Hat products that ship spring-ws-security, where the vulnerable Wss4jSecurityInterceptor resides, are limited to Red Hat Fuse 7. In Fuse deployments, this risk is further reduced when services enforce TLS for all SOAP endpoints, preventing the message capture that exploitation depends on.

Меры по смягчению последствий

Ensure all SOAP endpoints using Spring Web Services WS-Security are accessed exclusively over TLS. This prevents attackers from capturing valid SOAP messages in transit, which is a prerequisite for exploiting the replay cache bypass. Additionally, reduce the WSS4J timestamp acceptance window (timeToLive) from the default 300 seconds to the minimum value the application can tolerate, limiting the replay window for any messages that may be intercepted through other means.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-ws-securityFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-294
https://bugzilla.redhat.com/show_bug.cgi?id=2487804Spring Web Services: Spring Web Services: Replay protection bypass due to improper cache integration

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
2 месяца назад

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVSS3: 3.7
github
2 месяца назад

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

3.7 Low

CVSS3