CVE-2017-5653

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-04-18 16:59

Updated : 2023-11-07 02:49


NVD link : CVE-2017-5653

Mitre link : CVE-2017-5653

CVE.ORG link : CVE-2017-5653


JSON object : View

Products Affected

apache

  • cxf
CWE
CWE-295

Improper Certificate Validation