Show filters
48 Total Results
Displaying 1-10 of 48
Sort by:
Attacker Value
Unknown

CVE-2021-40690

Disclosure Date: September 19, 2021 (last updated November 08, 2023)
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Attacker Value
Unknown

CVE-2025-23184

Disclosure Date: January 21, 2025 (last updated February 12, 2025)
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Attacker Value
Unknown

CVE-2024-51764

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
0
Attacker Value
Unknown

CVE-2024-41172

Disclosure Date: July 19, 2024 (last updated August 08, 2024)
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Attacker Value
Unknown

CVE-2024-32007

Disclosure Date: July 19, 2024 (last updated July 20, 2024)
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 
Attacker Value
Unknown

CVE-2024-29736

Disclosure Date: July 19, 2024 (last updated August 23, 2024)
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
Attacker Value
Unknown

CVE-2024-28752

Disclosure Date: March 15, 2024 (last updated February 14, 2025)
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
0
Attacker Value
Unknown

CVE-2022-46364

Disclosure Date: December 13, 2022 (last updated November 08, 2023)
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
Attacker Value
Unknown

CVE-2022-46363

Disclosure Date: December 13, 2022 (last updated November 08, 2023)
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
Attacker Value
Unknown

CVE-2021-30468

Disclosure Date: June 16, 2021 (last updated November 08, 2023)
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.