Back

MEDIUM

cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate

Published Nov 4, 2012

Description

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check

Affected products

Remediation

Red Hat statement

Not vulnerable. Apache CXF is shipped with several Red Hat products, but the wsdl_first_https sample is not included. Without this sample code, the flaw is not exposed.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 4, 2012
Updated Aug 6, 2024
Reserved Nov 4, 2012
CISA Vulnrichment
Updated Jun 18, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Oct 16, 2012