Описание
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
A flaw was found in Spring Web Services. The security interceptor in the affected component did not properly integrate replay cache mechanisms. This vulnerability could allow a remote attacker to bypass replay protections for security tokens, such as UsernameToken nonces and SAML one-time-use elements. The consequence is a low integrity impact, where an attacker might be able to reuse tokens for unauthorized actions.
Отчет
Red Hat rates this vulnerability as Low impact with a CVSS score of 3.7, consistent with the upstream assessment. Attack Complexity is High (AC:H) because the attacker must first capture a valid SOAP message in transit and then replay it within the token acceptance window, which defaults to 300 seconds. Impact is limited to integrity (I:L), as a replayed message can only repeat an already-authorized operation with no effect on confidentiality or availability. Red Hat products that ship spring-ws-security, where the vulnerable Wss4jSecurityInterceptor resides, are limited to Red Hat Fuse 7. In Fuse deployments, this risk is further reduced when services enforce TLS for all SOAP endpoints, preventing the message capture that exploitation depends on.
Меры по смягчению последствий
Ensure all SOAP endpoints using Spring Web Services WS-Security are accessed exclusively over TLS. This prevents attackers from capturing valid SOAP messages in transit, which is a prerequisite for exploiting the replay cache bypass. Additionally, reduce the WSS4J timestamp acceptance window (timeToLive) from the default 300 seconds to the minimum value the application can tolerate, limiting the replay window for any messages that may be intercepted through other means.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | spring-ws-security | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.7 Low
CVSS3
Связанные уязвимости
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
3.7 Low
CVSS3