天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-92899 Apache WSS4J 令牌重放漏洞

影响攻击者可重放捕获的认证令牌,冒充合法用户发送请求

AI 研判

Apache WSS4J 在处理 UsernameToken 的 Nonce 时,将其以原始 base64 文本形式存入重放缓存,但认证时使用解码后的字节进行校验。由于同一字节序列存在多种 base64 编码写法,攻击者可在捕获的请求 Nonce 中插入空格,使密码摘要仍能通过验证,但令牌不再匹配缓存中记录的值,从而绕过重放检测。

影响范围

Apache WSS4J

受影响版本为配置了 nonce 重放缓存(如 Apache CXF 默认配置)且使用密码摘要(password digest)的 WSS4J 部署;官方修复版本为 4.0.2、3.0.6、2.4.4,具体受影响版本范围暂无公开信息。

漏洞详情

漏洞类型为认证绕过/重放攻击。成因是 Nonce 在缓存中以未解码的 base64 文本作为键,而认证逻辑使用解码后的字节,导致同一 Nonce 的等价 base64 变体(如添加空格)无法命中缓存。攻击者捕获一个已认证请求后,修改 Nonce 编码并重放,即可通过摘要校验并绕过重放缓存;由于 UsernameToken 不覆盖消息体,攻击者可在令牌过期前将其用于任意请求。

利用条件与风险

利用前提是攻击者能捕获到使用密码摘要的已认证请求,且目标启用了 nonce 重放缓存。实战中可导致会话/令牌重放、越权操作,CVSS 4.8 为中危。

修复建议

官方建议升级至 Apache WSS4J 4.0.2、3.0.6 或 2.4.4 版本,修复后缓存以解码后的 Nonce 作为键。临时缓解措施暂无公开信息。

原始情报

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker’s choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.