Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-46363

Опубликовано: 13 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.

A vulnerability was found in Apache CXF that could allow an attacker to perform a remote directory listing or code exfiltration. This issue only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, so the issue can only occur if the CXF service is misconfigured.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Migration Toolkit for Applications 6org.keycloak-keycloak-parentNot affected
Migration Toolkit for Runtimesorg.apache.cxf-cxf-apiWill not fix
Migration Toolkit for Runtimesorg.keycloak-keycloak-parentNot affected
Red Hat build of QuarkusCXFNot affected
Red Hat Data Grid 8CXFNot affected
Red Hat Decision Manager 7CXFOut of support scope
Red Hat Integration Camel Quarkus 1CXFNot affected
Red Hat JBoss Data Grid 7CXFOut of support scope
Red Hat JBoss Data Virtualization 6CXFOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2155681CXF: directory listing / code exfiltration

EPSS

Процентиль: 25%
0.00089
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.

CVSS3: 7.5
github
около 3 лет назад

Apache CXF vulnerable to Exposure of Sensitive Information

EPSS

Процентиль: 25%
0.00089
Низкий

7.5 High

CVSS3