This is an automated email from the ASF dual-hosted git repository.
coheigea pushed a commit to branch 2_4_x-fixes
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git
The following commit(s) were added to refs/heads/2_4_x-fixes by this push:
new a33a198f0 Enforce isAllowRSA15KeyTransportAlgorithm for the StAX layer
(#674)
a33a198f0 is described below
commit a33a198f01a95fc2e3a2d98a57341714170fc551
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Mon Sep 7 11:06:46 2026 +0100
Enforce isAllowRSA15KeyTransportAlgorithm for the StAX layer (#674)
---
.../impl/processor/input/WSSEncryptedKeyInputHandler.java | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git
a/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
b/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
index 31b617ea9..9716181a0 100644
---
a/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
+++
b/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
@@ -63,6 +63,20 @@ public class WSSEncryptedKeyInputHandler extends
XMLEncryptedKeyInputHandler {
}
}
+ // Reject RSA v1.5 key transport before key resolution or unwrap.
+ if (encryptionMethodType != null
+ &&
WSSConstants.NS_XENC_RSA15.equals(encryptionMethodType.getAlgorithm())
+ && !((WSSSecurityProperties)
securityProperties).isAllowRSA15KeyTransportAlgorithm()) {
+ final WSInboundSecurityContext wsInboundSecurityContext =
+ (WSInboundSecurityContext)
inputProcessorChain.getSecurityContext();
+ Boolean allowRSA15 =
+
wsInboundSecurityContext.get(WSSConstants.PROP_ALLOW_RSA15_KEYTRANSPORT_ALGORITHM);
+ if (allowRSA15 == null || !allowRSA15) {
+ throw new
WSSecurityException(WSSecurityException.ErrorCode.FAILED_CHECK,
+
WSSConstants.PROP_ALLOW_RSA15_KEYTRANSPORT_ALGORITHM);
+ }
+ }
+
super.handle(inputProcessorChain, encryptedKeyType,
responsibleXMLSecStartXMLEvent, securityProperties);
}