[MAVEN:GHSA-5JC8-8XHV-G8QM] Improper Input Validation in XFire

Severity Moderate
Affected Packages 1
CVEs 1

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Package Affected Version
pkg:maven/org.codehaus.xfire/xfire-core <= 1.2.6
ID
MAVEN:GHSA-5JC8-8XHV-G8QM
Severity
moderate
URL
https://github.com/advisories/GHSA-5jc8-8xhv-g8qm
Published
2022-05-17T01:38:40
(2 years ago)
Modified
2023-01-27T05:02:35
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.codehaus.xfire/xfire-core org.codehaus.xfire xfire-core <= 1.2.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...