Описание
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
A flaw was found in Apache Neethi. An attacker can exploit this vulnerability by crafting malicious WS-Policy documents that contain circular policy references. This can cause the policy normalization process to enter an infinite loop or excessive recursion, leading to a stack overflow or application hang. Consequently, a remote attacker can trigger a Denial of Service (DoS) condition.
Отчет
This Moderate flaw in Apache Neethi allows a remote attacker to trigger a Denial of Service condition. By crafting malicious WS-Policy documents with circular references, an attacker can cause the policy normalization process to enter an infinite loop or excessive recursion, leading to application instability or a hang. This can disrupt services relying on Apache Neethi for policy processing. In order to exploit this vulnerability, the attack should have enough privileges in the targeted system to include the maliciously crafted policy document or trick the user to consume it.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | neethi | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | neethi | Fix deferred | ||
| Red Hat Fuse 7 | neethi | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | neethi | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | neethi | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | neethi | Fix deferred | ||
| Red Hat Process Automation 7 | neethi | Fix deferred | ||
| Red Hat Single Sign-On 7 | neethi | Fix deferred | ||
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | neethi | Fixed | RHSA-2026:19835 | 20.05.2026 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Apache Neethi does not properly detect circular references in policy definitions.
6.5 Medium
CVSS3