CVE-2012-5575 – org.apache.cxf:cxf-rt-transports-http
Package
Manager: maven
Name: org.apache.cxf:cxf-rt-transports-http
Vulnerable Version: >=2.5.0 <2.5.10 || >=2.6.0 <2.6.7 || >=2.7.0 <2.7.4
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.12285 pctl0.93614
Details
Inadequate Encryption Strength in Apache CXF Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
Metadata
Created: 2022-05-13T01:09:21Z
Modified: 2022-07-13T15:29:33Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7v5v-9v8r-w864/GHSA-7v5v-9v8r-w864.json
CWE IDs: ["CWE-326"]
Alternative ID: GHSA-7v5v-9v8r-w864
Finding: F052
Auto approve: 1