ZeroHour

CVE-2017-5653

CVSS 3.0
5.3 medium
EPSS
11%p96
Published
()
Modified
Description

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

Vendors
apache
Products
cxf
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.