Vulnerability CVE-2015-5253


Published: 2015-11-18

Description:
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Apache -> CXF 

 References:
http://cxf.apache.org/security-advisories.data/CVE-2015-5253.txt.asc
http://rhn.redhat.com/errata/RHSA-2016-0321.html
http://www.openwall.com/lists/oss-security/2015/11/14/1
http://www.securitytracker.com/id/1034162
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commitdiff;h=845eccb6484b43ba02875c71e824db23ae4f20c0

Copyright 2024, cxsecurity.com

 

Back to Top