CVE-2015-0227: Improper Access Control in Apache WSS4J
(updated )
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to “wrapping attacks.”
References
Code Behaviors & Features
Detect and mitigate CVE-2015-0227 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →