Lucene search

K
osvGoogleOSV:GHSA-VJPC-VF4F-82QG
HistoryMay 13, 2022 - 1:09 a.m.

Improper Authentication in Apache CXF

2022-05-1301:09:22
Google
osv.dev
11

0.002 Low

EPSS

Percentile

52.7%

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

References

0.002 Low

EPSS

Percentile

52.7%