org.apache.cxf:apache-cxf
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.cxf:apache-cxfpage 1 of 1
- CVE-2018-8039HIGHCVSS 8.1✓ Fixed in 3.1.162018-07-02
vulnerable: 2.0.10 ... 3.1.9 (139 versions)
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection t…
- CVE-2019-12406MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.3.42019-11-06
vulnerable: 3.3.0, 3.3.1, 3.3.2, 3.3.3
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a ve…
- CVE-2019-12423HIGHCVSS 7.5EG 7.5✓ Fixed in 3.3.52020-01-16
vulnerable: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the publ…
- CVE-2019-17573MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.3.52020-01-16
vulnerable: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javas…
- CVE-2020-13954MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.4.12020-11-12
vulnerable: 3.4.0
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a maliciou…
- CVE-2021-22696HIGHCVSS 7.5EG 7.5✓ Fixed in 3.3.102021-04-02
vulnerable: 2.0.10 ... 3.3.9 (167 versions)
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "r…
- CVE-2021-30468HIGHCVSS 7.5EG 7.5✓ Fixed in 3.3.112021-06-16
vulnerable: 2.0.10 ... 3.3.9 (168 versions)
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apac…
Check whether org.apache.cxf:apache-cxf is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.cxf:apache-cxf CVEs against the assets you own.
Start Free Scan →