AI analysis
In Apache WSS4J’s streaming (StAX) code, a signature reference that uses the WS-Security STR-Transform leaves an internal “inside signed content” flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element still needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy that requires the SOAP Body to be signed can then be treated as satisfied even when the Body carries no signature, removing protection against XML Signature Wrapping; verification of signatures that are present is unaffected, and the DOM implementation is not affected. Applications that enforce WS-SecurityPolicy through WSS4J’s streaming path are affected and should move to 4.0.2, 3.0.6, or 2.4.4. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored.
What to do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4, matching the release line you use. Until then, do not rely on the streaming (StAX) enforcer for SignedParts or SignedElements; use the unaffected DOM code path where possible, and review SOAP services whose policy requires a signed Body.
Affected
| Apache WSS4J | Streaming (StAX) code before 2.4.4, 3.0.6, and 4.0.2; DOM code is not affected |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.