Uploaded image for project: 'Rampart'
  1. Rampart
  2. RAMPART-446

Rampart uses vulnerable version of WSS4J

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 1.7.1
    • 1.7.2
    • None
    • None

    Description

      Apache WSS4J has some security issues that have been known since 2015.  See https://ws.apache.org/wss4j/security_advisories.html Both are against any version of Apache WSS4J below version 1.6.17.  Looking at the pom.xml file for Apache Rampart on version 1.7.1, it appears that Rampart pulls down version 1.6.16, and hence is vulnerable.

      Attachments

        Activity

          People

            Unassigned Unassigned
            platanobailando Christopher
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: