Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 4.0

...

An XML Encryption backwards compatibility attack on Apache CXF is described by
CVE-2012-5575:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5575Image Removed

This attack relates to a previous security advisory CVE-2011-1096
(http://cxf.apache.org/note-on-cve-2011-1096.htmlImage Removed). CVE-2011-1096 exploited a
cryptographic weakness in the CBC mode of XML Encryption, to conduct chosen
ciphertext attacks leading to the recovery of the entire plaintext. The fix
for CVE-2011-1096 was to switch to use GCM instead of CBC. Please see the note
linked above for more information.

...