Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffm7-7r8g-77xm

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache CXF JMX Integration is vulnerable to a MITM attack

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the createMBServerConnectorFactory property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Пакеты

Наименование

org.apache.cxf:cxf-rt-management

maven
Затронутые версииВерсия исправления

< 3.2.13

3.2.13

Наименование

org.apache.cxf:cxf-rt-management

maven
Затронутые версииВерсия исправления

>= 3.3.0, < 3.3.6

3.3.6

EPSS

Процентиль: 44%
0.00216
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
почти 6 лет назад

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
nvd
почти 6 лет назад

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с ошибками при установлении соединения, позволяющая нарушителю получить несанкционрованный доступ к защищаемой информации

EPSS

Процентиль: 44%
0.00216
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200