CVE-2021-30468
- EPSS 0.4%
- Veröffentlicht 16.06.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:58
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF vers...
CVE-2021-22696
- EPSS 0.49%
- Veröffentlicht 02.04.2021 10:15:12
- Zuletzt bearbeitet 21.11.2024 05:50:28
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" par...
CVE-2020-13954
- EPSS 8.03%
- Veröffentlicht 12.11.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:13
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to ...
CVE-2020-1954
- EPSS 0.1%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:43
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to...
CVE-2011-2487
- EPSS 0.14%
- Veröffentlicht 11.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:28:23
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
CVE-2019-17573
- EPSS 15.54%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:33
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into ...
CVE-2019-12423
- EPSS 1.32%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from...
CVE-2019-12419
- EPSS 14.28%
- Veröffentlicht 06.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is...
CVE-2019-12406
- EPSS 2.07%
- Veröffentlicht 06.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:46
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large nu...
CVE-2018-8039
- EPSS 1.91%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:09
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to ma...