logo

CVE-2012-5575 org.apache.cxf:cxf-rt-transports-http

Package

Manager: maven
Name: org.apache.cxf:cxf-rt-transports-http
Vulnerable Version: >=2.5.0 <2.5.10 || >=2.6.0 <2.6.7 || >=2.7.0 <2.7.4

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.12285 pctl0.93614

Details

Inadequate Encryption Strength in Apache CXF Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

Metadata

Created: 2022-05-13T01:09:21Z
Modified: 2022-07-13T15:29:33Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7v5v-9v8r-w864/GHSA-7v5v-9v8r-w864.json
CWE IDs: ["CWE-326"]
Alternative ID: GHSA-7v5v-9v8r-w864
Finding: F052
Auto approve: 1