CVE-2017-5653

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

Information

Published : 2017-04-18 16:59

Updated : 2021-06-16 12:15


NVD link : CVE-2017-5653

Mitre link : CVE-2017-5653


JSON object : View

Products Affected

apache

  • cxf
CWE
CWE-295

Improper Certificate Validation