Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg32-686q-qh6x

Опубликовано: 26 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache CXF has an LDAP injection vulnerability

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Пакеты

Наименование

org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

maven
Затронутые версииВерсия исправления

= 4.2.0

4.2.1

Наименование

org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

maven
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.6

4.1.6

Наименование

org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

maven
Затронутые версииВерсия исправления

< 3.6.11

3.6.11

EPSS

Процентиль: 49%
0.00694
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-90

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS3: 9.8
nvd
3 месяца назад

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость сервиса XKMS (XML Key Management Specification) каркаса для веб-сервисов Apache CXF, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 49%
0.00694
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-90