CVE-2012-0803Page added by Colm O hEigeartaigh---- CVE-2012-0803: Apache CXF does not validate UsernameToken policies correctly Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache CXF 2.4.5 and 2.5.1 Description: CXF does not validate a WS-Security UsernameToken received as part A malicious client could send a request to the endpoint with no UsernameToken, This has been fixed in revision: http://svn.apache.org/viewvc?view=revision&revision=1233457 This issue was a regression in CXF 2.4.5 and 2.5.1. The vulnerability does not Migration: CXF 2.4.5 users should upgrade to 2.4.6 as soon as possible. References: http://cxf.apache.org/security-advisories.html ---- iQEcBAEBAgAGBQJPMAVXAAoJEGe/gLEK1TmD6y0H/2aP3A02qoFKeV0oYj7y8BCv
Change Notification Preferences
View Online
|
Add Comment
|
