JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-295"
],
"github_reviewed_at": "2022-07-01T11:59:24Z",
"github_reviewed": true,
"nvd_published_at": "2017-04-18T16:59:00Z"
}