Vulnerability GHSA-3w37-5p3p-jv92

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
December 13, 2022 at 03:30 PM UTC
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5

Summary

Apache CXF vulnerable to Exposure of Sensitive Information

Details

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.

Impacted packages

Timeline

Published
3 years ago
December 13, 2022 at 03:30 PM UTC
Fixed (3.4.10)
Unknown
Unknown
Fixed (3.5.5)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 08:04 AM UTC