Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-254q-rp36-v2m8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Missing XML Validation in Apache CXF

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

Пакеты

Наименование

org.apache.cxf:cxf-rt-frontend-jaxrs

maven
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.10

2.5.10

Наименование

org.apache.cxf:cxf-rt-frontend-jaxrs

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.7

2.6.7

Наименование

org.apache.cxf:cxf-rt-frontend-jaxrs

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.4

2.7.4

EPSS

Процентиль: 95%
0.203
Средний

Дефекты

CWE-112

Связанные уязвимости

redhat
около 12 лет назад

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

nvd
почти 12 лет назад

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

EPSS

Процентиль: 95%
0.203
Средний

Дефекты

CWE-112