CVE-2013-0239: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate
(updated )
When the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
References
Detect and mitigate CVE-2013-0239 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →