Impact
The flaw allows an attacker who captures a valid WSSE digest authentication header to reuse it and gain access to the victim's AtomPub resources. Because the implementation does not enforce nonce uniqueness or timestamp freshness, a replayed header is treated as fresh and accepted, providing a direct authentication bypass.
Affected Systems
The issue affects Apache Roller installations that use the AtomPub API with WSSE authentication enabled and rely on plaintext‑compatible password storage. Specifically, Apache Roller 6.1.5 and earlier are vulnerable where the non‑default AtomPub service is configured to use WSSE.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability with a high impact if exploited. There is no EPSS score available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves network capture of the AtomPub traffic; upon intercepting a WSSE header, an attacker can replay it without modification. The vulnerability remains exploitable until WSSE is disabled or Railsimin upgraded to a version that removes WSSE as an AtomPub authentication method.
OpenCVE Enrichment