CVE-2012-2378: Medium severity apache cxf vulnerability
Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2378?
CVE-2012-2378 is considered to have a high severity due to its potential exploitation by remote attackers.
Which versions of Apache CXF are affected by CVE-2012-2378?
CVE-2012-2378 affects Apache CXF versions 2.4.5 to 2.4.7, 2.5.1 to 2.5.3, and 2.6.x before 2.6.1.
How do I fix CVE-2012-2378?
To fix CVE-2012-2378, update Apache CXF to version 2.6.1 or higher.
What type of attacks can exploit CVE-2012-2378?
CVE-2012-2378 can be exploited to bypass WS-SecurityPolicy 1.1 policies, which may lead to unauthorized access and data compromise.
Is there a workaround for CVE-2012-2378 if I cannot update?
There is no official workaround for CVE-2012-2378, and updating to the patched version is strongly recommended.