Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f93p-f762-vr53

Опубликовано: 10 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Reflected Cross-Site Scripting in Apache CXF

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

Ссылки

Пакеты

Наименование

org.apache.cxf:apache-cxf

maven
Затронутые версииВерсия исправления

< 3.2.12

3.2.12

Наименование

org.apache.cxf:apache-cxf

maven
Затронутые версииВерсия исправления

>= 3.3.0, < 3.3.5

3.3.5

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

< 3.2.12

3.2.12

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 3.3.0, < 3.3.5

3.3.5

EPSS

Процентиль: 95%
0.16126
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
около 6 лет назад

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
nvd
около 6 лет назад

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS3: 6.1
fstec
около 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку

EPSS

Процентиль: 95%
0.16126
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79