AI analysis
Apache WSS4J can confuse child elements of an EncryptedHeader and treat an attacker-controlled plaintext element as the decrypted header. That wrong selection means the library may apply confidentiality protection to the wrong content and can let a message pass policy checks that depend on the decrypted header. The issue affects applications and frameworks that use unfixed WSS4J for WS-Security message protection. Apache recommends upgrading to 4.0.2, 3.0.6, or 2.4.4, which contain the fix. There is no known public proof of concept, the flaw is not listed in CISA KEV, and exploitation in the wild is not known.
What to do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4, matching the release line you already use. After the upgrade, confirm the patched library is what actually processes WS-Security messages and recheck policies that treat EncryptedHeader as proof of confidentiality coverage.
Affected
| Apache WSS4J | Fixed in 2.4.4, 3.0.6, and 4.0.2; earlier releases on those lines are the ones users are told to replace |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.