CVE Vulnerabilities

CVE-2015-5253

Published: Nov 18, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a wrapping attack.

Affected Software

NameVendorStart VersionEnd Version
CxfApache*2.7.18 (excluding)
CxfApache3.0.0 (including)3.0.7 (excluding)
CxfApache3.1.0 (including)3.1.3 (excluding)
Red Hat JBoss Fuse 6.2RedHat*

References