Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
2.5.7, 2.6.4, 2.7.1
-
None
-
Unknown
Description
The UsernameTokenInterceptor, which is used to send + process WS-Security UsernameTokens using a streaming implementation rather than WSS4J, is not caching nonces, and hence is vulnerable to replay attacks.