Описание
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Ссылки
- Mailing ListVendor Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.5.9 (исключая)Версия от 3.6.0 (включая) до 3.6.4 (исключая)Версия от 4.0.0 (включая) до 4.0.5 (исключая)
Одно из
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.0128
Низкий
7.5 High
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
redhat
около 2 лет назад
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
CVSS3: 5.3
github
около 2 лет назад
Apache CXF Denial of Service vulnerability in JOSE
CVSS3: 7.5
fstec
около 2 лет назад
Уязвимость компонента JOSE каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 68%
0.0128
Низкий
7.5 High
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo