[MAVEN:GHSA-5WQF-H3R3-GXVH] Uncontrolled Resource Consumption in Apache CXF

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

Package Affected Version
pkg:maven/org.apache.cxf/cxf-core >= 2.7.0, < 2.7.11
pkg:maven/org.apache.cxf/cxf-core < 2.6.14
ID
MAVEN:GHSA-5WQF-H3R3-GXVH
Severity
moderate
URL
https://github.com/advisories/GHSA-5wqf-h3r3-gxvh
Published
2022-05-13T01:09:20
(2 years ago)
Modified
2023-12-21T21:52:10
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core >= 2.7.0 < 2.7.11
Fixed pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core = 2.7.11
Affected pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core < 2.6.14
Fixed pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core = 2.6.14
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...