Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12406

Опубликовано: 06 нояб. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6cxfOut of support scope
Red Hat BPM Suite 6cxf-coreOut of support scope
Red Hat JBoss BRMS 6cxfOut of support scope
Red Hat JBoss BRMS 6cxf-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 7cxfNot affected
Red Hat JBoss Enterprise Application Platform 7cxf-coreNot affected
Red Hat JBoss Fuse 6cxf-coreOut of support scope
Red Hat OpenShift Application Runtimescxf-coreAffected
Red Hat Single Sign-On 7cxf-coreNot affected
Red Hat support for Spring Bootcxf-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1816170cxf: does not restrict the number of message attachments

EPSS

Процентиль: 88%
0.04134
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

CVSS3: 6.5
github
около 6 лет назад

Potential DOS attack due to unrestricted attachment count in messages

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 88%
0.04134
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2019-12406