Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05OXYzLTl4MzUtYzV2Zs3wUw
Improper Authentication in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
Permalink: https://github.com/advisories/GHSA-99v3-9x35-c5vfJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OXYzLTl4MzUtYzV2Zs3wUw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: over 1 year ago
Identifiers: GHSA-99v3-9x35-c5vf, CVE-2014-3623
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-3623
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97754
- https://issues.apache.org/jira/browse/WSS-511
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- http://rhn.redhat.com/errata/RHSA-2015-0236.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0850.html
- http://rhn.redhat.com/errata/RHSA-2015-0851.html
- http://seclists.org/oss-sec/2014/q4/437
- https://github.com/advisories/GHSA-99v3-9x35-c5vf
Affected Packages
maven:org.apache.wss4j:wss4j-ws-security-dom
Dependent packages: 89Dependent repositories: 241
Downloads:
Affected Version Ranges: >= 2.0.0, < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.1.10, 2.1.11, 2.1.12, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 3.0.0, 3.0.1, 3.0.2, 3.0.3
maven:org.apache.ws.security:wss4j
Dependent packages: 122Dependent repositories: 1,332
Downloads:
Affected Version Ranges: < 1.6.17
Fixed in: 1.6.17
All affected versions: 1.6.8, 1.6.9, 1.6.10, 1.6.11, 1.6.12, 1.6.13, 1.6.14, 1.6.15, 1.6.16
All unaffected versions: 1.6.17, 1.6.18, 1.6.19