First published: Wed Nov 18 2015(Updated: )
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CXF | <2.7.18 | |
Apache CXF | >=3.0.0<3.0.7 | |
Apache CXF | >=3.1.0<3.1.3 | |
maven/org.apache.cxf:cxf-rt-rs-security-sso-saml | >=3.1.0<=3.1.2 | 3.1.3 |
maven/org.apache.cxf:cxf-rt-rs-security-sso-saml | >=3.0.0<=3.0.6 | 3.0.7 |
maven/org.apache.cxf:cxf-rt-rs-security-sso-saml | <=2.7.17 | 2.7.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.