AI analysis
Apache WSS4J's StAX streaming WS-SecurityPolicy validator can turn certain relative or unsupported XPath expressions into paths that never match the actual XML element path. A remote SOAP peer can then send a required element without the signature or encryption the policy expects, so element-protection checks are skipped. Services that rely on that streaming validator may accept SOAP messages that violate required protection. Users of Apache WSS4J on the affected release lines are advised to move to 4.0.2, 3.0.6, or 2.4.4. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored.
What to do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4 for the release line in use, including applications and frameworks that bundle the library. After upgrading, recheck SOAP services that use the StAX streaming WS-SecurityPolicy validator so required elements are still enforced as signed or encrypted.
Affected
| Apache Software Foundation Apache WSS4J | Releases before the fixes 4.0.2, 3.0.6, and 2.4.4 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.