CVE-2017-5653

Description

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
3.167

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-5656,CVE-2017-5653 are fixed in Apache-CXF-Core 3.1.11Windows
Vulnerabilities CVE-2017-5656,CVE-2017-5653 are fixed in Apache-CXF-Core 3.0.13Windows
Vulnerabilities CVE-2017-5656,CVE-2017-5653 are fixed in Apache-CXF-Core for Linux 3.1.11Linux
Vulnerabilities CVE-2017-5656,CVE-2017-5653 are fixed in Apache-CXF-Core for Linux 3.0.13Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234