Lucene search

K
osvGoogleOSV:GHSA-HGG6-8X62-M9GF
HistoryMay 13, 2022 - 1:09 a.m.

Improper Certificate Validation in Apache CXF

2022-05-1301:09:19
Google
osv.dev
11

0.003 Low

EPSS

Percentile

71.2%

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

References

0.003 Low

EPSS

Percentile

71.2%