Vulnerability GHSA-3w37-5p3p-jv92
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
December 13, 2022 at 03:30 PM UTC
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
Summary
Apache CXF vulnerable to Exposure of Sensitive Information
Details
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
Critical
3 months ago
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
Medium Risk
1 year ago
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
4.1.0 GHSA-36wv-v2qp-v4g4
4.1.0 GHSA-36wv-v2qp-v4g4
High Risk
1 year ago
Apache CXF: Denial of Service vulnerability with temporary files
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
Critical
3 years ago
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
Impacted packages
Timeline
Published
3 years ago
December 13, 2022 at 03:30 PM UTC
Fixed (3.4.10)
Unknown
Unknown
Fixed (3.5.5)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 08:04 AM UTC