CVE Vulnerabilities

CVE-2015-5253

Published: Nov 18, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a wrapping attack.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 2.7.18 (excluding)
Cxf Apache 3.0.0 (including) 3.0.7 (excluding)
Cxf Apache 3.1.0 (including) 3.1.3 (excluding)
Red Hat JBoss Fuse 6.2 RedHat *

References