Skip to content

XML Signature/Encryption Not Validated in Apache CXF

High severity GitHub Reviewed Published May 13, 2022 to the GitHub Advisory Database • Updated Dec 21, 2023

Package

maven org.apache.cxf:cxf (Maven)

Affected versions

>= 2.4.0, < 2.4.8
>= 2.5.0, < 2.5.4
>= 2.6.0, < 2.6.1

Patched versions

2.4.8
2.5.4
2.6.1

Description

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

References

Published by the National Vulnerability Database Jan 3, 2013
Published to the GitHub Advisory Database May 13, 2022
Reviewed Jul 13, 2022
Last updated Dec 21, 2023

Severity

High

EPSS score

0.830%
(82nd percentile)

Weaknesses

No CWEs

CVE ID

CVE-2012-2379

GHSA ID

GHSA-2g99-c67p-56hm

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.