Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pff-fmh2-4mmf

Опубликовано: 19 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Apache CXF Denial of Service vulnerability in JOSE

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

Пакеты

Наименование

org.apache.cxf:cxf-rt-rs-security-jose

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.5

4.0.5

Наименование

org.apache.cxf:cxf-rt-rs-security-jose

maven
Затронутые версииВерсия исправления

>= 3.6.0, < 3.6.4

3.6.4

Наименование

org.apache.cxf:cxf-rt-rs-security-jose

maven
Затронутые версииВерсия исправления

< 3.5.9

3.5.9

EPSS

Процентиль: 68%
0.0128
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 лет назад

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

CVSS3: 7.5
nvd
около 2 лет назад

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость компонента JOSE каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.0128
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-20