AI analysis
An authentication bypass in the DOM security processor of Apache WSS4J lets unauthenticated remote attackers forge SOAP messages that the service treats as authenticated. The flaw is triggered by a crafted unsigned SAML sender-vouches assertion that contains an attacker-controlled key. An attacker can thereby impersonate a trusted sender and invoke web-service operations that rely on that assertion for authentication. Applications and services that validate WS-Security with a vulnerable Apache WSS4J release are affected; the issue is fixed in 2.4.4, 3.0.6, and 4.0.2. No public proof of concept is known, the CVE is not in the CISA KEV catalog, and CVSS has not yet been scored.
What to do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4 and redeploy every application that bundles the library, confirming the version actually loaded at runtime. Until then, limit network exposure of SOAP endpoints that accept SAML sender-vouches assertions and treat those assertions as untrusted.
Affected
| Apache WSS4J | Fixed in 2.4.4, 3.0.6, and 4.0.2; earlier releases addressed by those upgrades (exact vulnerable ranges not stated in the advisory) |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.