CVE-2017-5653
Improper Certificate Validation in Apache CXF
5.3
MEDIUM
CVSS 3.1
EPSS 11.2%
Description
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
How to fix CVE-2017-5653
To remediate CVE-2017-5653, upgrade the affected package to a fixed version below.
- Maven/org.apache.cxf:cxf-core—upgrade to 3.1.11 or later
Is CVE-2017-5653 being exploited?
Moderate — EPSS is 11.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 3.1.0, < 3.1.11
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |