Описание
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.4 (исключая)
cpe:2.3:a:apache:cxf_fediz:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.40655
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
больше 7 лет назад
High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3
EPSS
Процентиль: 97%
0.40655
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20