CVE-2015-5253: Medium severity apache cxf vulnerability
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5253?
CVE-2015-5253 is classified as a high-severity vulnerability due to its ability to allow remote authenticated users to bypass authentication.
How do I fix CVE-2015-5253?
To fix CVE-2015-5253, upgrade Apache CXF to version 2.7.18, 3.0.7, or 3.1.3 or later.
Which versions of Apache CXF are affected by CVE-2015-5253?
CVE-2015-5253 affects Apache CXF versions prior to 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3.
What type of attack is associated with CVE-2015-5253?
CVE-2015-5253 is related to a 'wrapping attack' that exploits crafted SAML responses.
Can unpatched versions of Apache CXF lead to security risks?
Yes, unpatched versions of Apache CXF would expose systems to the risk of authentication bypass as described in CVE-2015-5253.