Apache CXF vulnerable to Exposure of Sensitive Information
High severity
GitHub Reviewed
Published
Dec 13, 2022
to the GitHub Advisory Database
•
Updated Sep 7, 2023
Package
Affected versions
< 3.4.10
>= 3.5.0, < 3.5.5
Patched versions
3.4.10
3.5.5
Description
Published by the National Vulnerability Database
Dec 13, 2022
Published to the GitHub Advisory Database
Dec 13, 2022
Reviewed
Dec 13, 2022
Last updated
Sep 7, 2023
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
References