[ https://issues.apache.org/jira/browse/AXIS2C-1694?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16300285#comment-16300285 ]
Matthew Kornfield commented on AXIS2C-1694: ------------------------------------------- [~bblough] Ticket created > CVE-2012-4418 - "XML Signature wrapping attack" > ----------------------------------------------- > > Key: AXIS2C-1694 > URL: https://issues.apache.org/jira/browse/AXIS2C-1694 > Project: Axis2-C > Issue Type: Bug > Reporter: Matthew Kornfield > Priority: Critical > > Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4418 to > the following vulnerability: > Name: CVE-2012-4418 > URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4418 > Assigned: 20120821 > Reference: > http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf > Apache Axis2 allows remote attackers to forge messages and bypass > authentication via an "XML Signature wrapping attack." -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: c-dev-unsubscr...@axis.apache.org For additional commands, e-mail: c-dev-h...@axis.apache.org