CVE Vulnerabilities

CVE-2012-2378

Published: Jan 05, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

Affected Software

Name Vendor Start Version End Version
Cxf Apache 2.4.5 (including) 2.4.5 (including)
Cxf Apache 2.4.6 (including) 2.4.6 (including)
Cxf Apache 2.4.7 (including) 2.4.7 (including)

References