----BEGIN PGP SIGNED MESSAGE----
CVE-2012-2378: Apache CXF does not pick up some child policies of
WS-SecurityPolicy 1.1 SupportingToken policy assertions on the client side.
Vendor: The Apache Software Foundation
Apache CXF 2.4.5 to 2.4.7
Apache CXF 2.5.1 to 2.5.3
Apache CXF 2.6.0
None of the following child policies of a WS-SecurityPolicy 1.1
(.*)SupportingToken policy are picked up on the client side:
Note that all of these policies are picked up on the client side in the most
common use-cases, for example when an AlgorithmSuite is specified under a
security binding, or when a SignedParts Element is specified per-operation or
per-binding. They only do not apply when a SupportingToken is used to sign
or encrypt some part or element, for example:
<sp:Header Name="To" Namespace="http://www.w3.org/2005/08/addressing" />
Also note that this does not apply for the WS-SecurityPolicy 1.2 namespace,
but only for the older WS-SecurityPolicy 1.1 namespace of:
This has been fixed in revision:
The versions that are affected are CXF 2.4.5 to 2.4.7, CXF 2.5.1 to 2.5.3, and
CXF 2.6.0. The vulnerability does not exist in CXF 2.3.10, CXF 2.4.4 or 2.5.0.
CXF 2.4.5 to 2.4.7 users should upgrade to 2.4.8 as soon as possible.
CXF 2.5.1 to 2.5.3 users should upgrade to 2.5.4 as soon as possible.
CXF 2.6.0 users should upgrade to 2.6.1 as soon as possible.
----BEGIN PGP SIGNATURE----
Version: GnuPG v1.4.11 (GNU/Linux)
----END PGP SIGNATURE----