CVE-2013-0239 PUBLISHED CVSS 5 MEDIUM

UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate

EPSS 2.65% · 85.6th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
2.65%
85.6th percentile

Affected Products

VendorProductVersions
Mavenorg.apache.cxf:cxf-rt-frontend-jaxrs0, 0, 0
Mavenorg.apache.cxf:cxf-rt-ws-security2.4.1, 2.4.1, 2.4.1
n/an/an/a, n/a, n/a

Timeline

References

…and 4 more

Open in Interactive Console →