PT-2026-103133 · Apache · Wss4J
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WSS4J versions prior to 4.0.2
WSS4J versions prior to 3.0.6
WSS4J versions prior to 2.4.4
Description
In the streaming (StAX) code, a signature reference using the WS-Security STR-Transform causes an internal flag indicating content is signed to remain permanently set. The WS-SecurityPolicy enforcer relies on this flag to determine if an element requires checking; consequently, it ceases evaluating SignedParts and SignedElements for the remainder of the message. This allows a policy requiring the SOAP Body to be signed to be satisfied even if the Body lacks a signature, which eliminates protection against XML Signature Wrapping (a technique where an attacker modifies the XML structure to bypass security checks). Signature verification and DOM code remain unaffected.
Recommendations
Upgrade to version 4.0.2.
Upgrade to version 3.0.6.
Upgrade to version 2.4.4.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wss4J