CVE-2012-5786
published 2012-11-04CVE-2012-5786: The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server…
PriorityP424medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.08%
61.8th percentile
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | <= 2.6.17 | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
vendor_redhat·2012-10-16·CVSS 5.8
CVE-2012-5786 [MEDIUM] cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check
Statement: Not vulnerable. Apache CXF is shipped with several Red Hat products, but the wsdl_first_https sample is not included. Without this sample code, the flaw is not exposed.
GHSA
GHSA-4267-v6qh-xchc: ** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2
ghsa_unreviewed·2022-05-14
CVE-2012-5786 [MEDIUM] CWE-20 GHSA-4267-v6qh-xchc: ** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2
** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
bugzilla·2012-11-05·CVSS 5.8
CVE-2012-5786 [MEDIUM] CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the
Bugzilla
CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
bugzilla·2012-11-05·CVSS 5.8
CVE-2012-5786 [MEDIUM] CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
CVE-2012-5786 cxf: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5786 to the following vulnerability:
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
References:
[1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
[2] https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html
[3] http://www.sigsac.org
2012-11-04
Published