CVE-2012-2379: Critical severity apache cxf vulnerability
Published Jan 3, 2013
·Updated
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
Affected Software
16 affected componentsFixes available
maven/org.apache.cxf:cxf>=2.6.0<2.6.1
2.6.1
maven/org.apache.cxf:cxf>=2.5.0<2.5.4
2.5.4
maven/org.apache.cxf:cxf>=2.4.0<2.4.8
2.4.8
Apache CXF=2.4.0
Apache CXF=2.4.1
Apache CXF=2.4.2
Apache CXF=2.4.3
Apache CXF=2.4.4
Apache CXF=2.4.5
Apache CXF=2.4.6
Apache CXF=2.4.7
Apache CXF=2.5.0
Apache CXF=2.5.1
Apache CXF=2.5.2
Apache CXF=2.5.3
Apache CXF=2.6.0
Remediation
Patch Available
Event History
Jan 3, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
May 13, 2022
Advisory Published
01:09 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-2379?
CVE-2012-2379 is considered to have an unspecified impact and attack vectors.
2
Which versions of Apache CXF are affected by CVE-2012-2379?
Apache CXF versions prior to 2.4.8, 2.5.4, and 2.6.1 are vulnerable as per CVE-2012-2379.
3
How do I fix CVE-2012-2379?
To remediate CVE-2012-2379, upgrade to Apache CXF versions 2.4.8, 2.5.4, or 2.6.1 or later.
4
What types of attacks can exploit CVE-2012-2379?
CVE-2012-2379 may allow attackers to manipulate XML signatures or encryption in specific scenarios.
5
Is there a workaround for CVE-2012-2379?
There are no known workarounds for CVE-2012-2379, so upgrading is the recommended action.