[MAVEN:GHSA-6R5V-HP32-FJQW] Improper Access Control in Apache WSS4J

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

Package Affected Version
pkg:maven/org.apache.ws.security/wss4j >= 2.0.0, < 2.02
pkg:maven/org.apache.ws.security/wss4j < 1.6.17
ID
MAVEN:GHSA-6R5V-HP32-FJQW
Severity
moderate
URL
https://github.com/advisories/GHSA-6r5v-hp32-fjqw
Published
2022-05-14T02:57:28
(2 years ago)
Modified
2023-01-27T05:02:21
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.ws.security/wss4j org.apache.ws.security wss4j >= 2.0.0 < 2.02
Fixed pkg:maven/org.apache.ws.security/wss4j org.apache.ws.security wss4j = 2.02
Affected pkg:maven/org.apache.ws.security/wss4j org.apache.ws.security wss4j < 1.6.17
Fixed pkg:maven/org.apache.ws.security/wss4j org.apache.ws.security wss4j = 1.6.17
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...