logo

Database

Improper authorization control for web services In org.apache.cxf:cxf

Description

Improper Authentication in Apache CXF The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/cxf/commit/0cbc56618b6048847debe670d54919e2277444012. https://github.com/apache/cxf/commit/1a6b532d53a7b98018871982049e4b0c80dc837c3. https://github.com/apache/cxf/commit/94a98b3fe9c79e2cf3941acbbad216ba54999bc04. https://github.com/apache/cxf/commit/d99f96aa970d9f2faa8ed45e278a403af48757ae5. https://github.com/apache/cxf/commit/db11c9115f31e171de4622149f157d8283f6c7206. https://github.com/apache/cxf/commit/e0cdf873942b4d3fbc253e8ce6bb6fce3898019d7. https://github.com/apache/cxf/commit/e733c692e933a7f82424d3744aace9304cd5d4f68. https://web.archive.org/web/20130216044418/http://www.securityfocus.com:80/bid/578749. https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E10. https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E11. https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E12. https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E13. https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E14. https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E15. https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E16. https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E17. https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E18. https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E19. https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E20. https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E21. https://issues.jboss.org/browse/JBWS-357522. https://issues.apache.org/jira/browse/CXF-462923. https://github.com/apache/cxf24. https://exchange.xforce.ibmcloud.com/vulnerabilities/8198025. http://cxf.apache.org/cve-2012-5633.html26. http://packetstormsecurity.com/files/120213/Apache-CXF-WS-Security-URIMappingInterceptor-Bypass.html27. http://rhn.redhat.com/errata/RHSA-2013-0256.html28. http://rhn.redhat.com/errata/RHSA-2013-0257.html29. http://rhn.redhat.com/errata/RHSA-2013-0258.html30. http://rhn.redhat.com/errata/RHSA-2013-0259.html31. http://rhn.redhat.com/errata/RHSA-2013-0726.html32. http://rhn.redhat.com/errata/RHSA-2013-0743.html33. http://rhn.redhat.com/errata/RHSA-2013-0749.html34. http://seclists.org/fulldisclosure/2013/Feb/3935. http://stackoverflow.com/questions/7933293/why-does-apache-cxf-ws-security-implementation-ignore-get-requests36. http://svn.apache.org/viewvc?view=revision&revision=140932437. http://svn.apache.org/viewvc?view=revision&revision=1420698