Lucene search

K
githubGitHub Advisory DatabaseGHSA-XF9F-32GH-H2W4
HistoryMay 13, 2022 - 1:09 a.m.

Improper Authentication in Apache CXF

2022-05-1301:09:21
CWE-287
GitHub Advisory Database
github.com
14

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.002 Low

EPSS

Percentile

61.9%

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

Affected configurations

Vulners
Node
org.apache.cxf\Matchcxf
OR
org.apache.cxf\Matchcxf
OR
org.apache.cxf\Matchcxf

References

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.002 Low

EPSS

Percentile

61.9%