Show filters
48 Total Results
Displaying 1-10 of 48
Sort by:
Attacker Value
Unknown
CVE-2021-40690
Disclosure Date: September 19, 2021 (last updated November 08, 2023)
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
1
Attacker Value
Unknown
CVE-2025-23184
Disclosure Date: January 21, 2025 (last updated February 12, 2025)
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
0
Attacker Value
Unknown
CVE-2024-51764
Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
0
Attacker Value
Unknown
CVE-2024-41172
Disclosure Date: July 19, 2024 (last updated August 08, 2024)
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
0
Attacker Value
Unknown
CVE-2024-32007
Disclosure Date: July 19, 2024 (last updated July 20, 2024)
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
0
Attacker Value
Unknown
CVE-2024-29736
Disclosure Date: July 19, 2024 (last updated August 23, 2024)
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
0
Attacker Value
Unknown
CVE-2024-28752
Disclosure Date: March 15, 2024 (last updated February 14, 2025)
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
0
Attacker Value
Unknown
CVE-2022-46364
Disclosure Date: December 13, 2022 (last updated November 08, 2023)
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
0
Attacker Value
Unknown
CVE-2022-46363
Disclosure Date: December 13, 2022 (last updated November 08, 2023)
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
0
Attacker Value
Unknown
CVE-2021-30468
Disclosure Date: June 16, 2021 (last updated November 08, 2023)
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
0