Files
CVEs-PoC/2012/CVE-2012-2379.md
2025-09-29 21:09:30 +02:00

733 B

CVE-2012-2379

Description

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

POC

Reference

No PoCs from references.

Github