Apache

Cxf

43 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Published 16.06.2021 12:15:12
  • Last modified 21.11.2024 06:03:58

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF vers...

  • EPSS 0.49%
  • Published 02.04.2021 10:15:12
  • Last modified 21.11.2024 05:50:28

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" par...

  • EPSS 8.03%
  • Published 12.11.2020 13:15:11
  • Last modified 21.11.2024 05:02:13

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to ...

  • EPSS 0.1%
  • Published 01.04.2020 21:15:14
  • Last modified 21.11.2024 05:11:43

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to...

  • EPSS 0.14%
  • Published 11.03.2020 16:15:11
  • Last modified 21.11.2024 01:28:23

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

  • EPSS 15.54%
  • Published 16.01.2020 18:15:11
  • Last modified 21.11.2024 04:32:33

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into ...

  • EPSS 1.32%
  • Published 16.01.2020 18:15:11
  • Last modified 21.11.2024 04:22:48

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from...

  • EPSS 14.28%
  • Published 06.11.2019 21:15:11
  • Last modified 21.11.2024 04:22:48

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is...

  • EPSS 2.07%
  • Published 06.11.2019 21:15:11
  • Last modified 21.11.2024 04:22:46

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large nu...

  • EPSS 1.91%
  • Published 02.07.2018 13:29:00
  • Last modified 21.11.2024 04:13:09

It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to ma...