Loading...
Loading...
Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
January 5, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-2378
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.