Impact
This vulnerability arises because the Apache CXF JAX‑RS XML Security interceptors do not confirm that all XML fragments delivered to the application are covered by a cryptographic signature. An attacker who can supply a document signed with a trusted private key may embed malicious content before or after the signed portion, effectively wrapping the unsigned payload. The application then processes the wrapped content as if it were fully authenticated, potentially allowing unauthorized data manipulation, configuration changes, or execution of tampered code, representing a privilege‑escalation or integrity‑compromise risk.
Affected Systems
The issue affects releases of Apache CXF that contain the JAX‑RS XML Security module prior to the fixes. Vendors affected include the Apache Software Foundation's Apache CXF. Versions older than 4.2.4, 4.1.9 or 3.6.13 are vulnerable; upgrading to these releases or later eliminates the flaw. The vulnerability does not apply to product variants beyond the base JAX‑RS XML Security component.
Risk and Exploitability
The flaw does not require local code execution or special privileges to exploit; it only requires access to a signed XML document from a trusted key. Because the signed part can be freely chosen, an attacker can craft a document that includes arbitrary unsigned elements. The lack of an EPSS or CVSS metric in the data means the ease of exploitation is not quantified, but the threat is present for any deployment that accepts signed XML without integrity checks. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at the time of data publication.
OpenCVE Enrichment