PT-2014-5406 · Apache · Apache Cxf
Publicado
2014-10-30
·
Atualizado
2022-05-13
·
CVE-2014-3584
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache CXF versions 2.6.10 and earlier, 2.7.x before 2.7.8, 3.0.x before 3.0.1
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop. This can be achieved by sending a crafted SAML token in the authorization header of a request to a JAX-RS service.
Recommendations
For Apache CXF versions 2.6.10 and earlier, update to version 2.6.11 or later.
For Apache CXF versions 2.7.x before 2.7.8, update to version 2.7.8 or later.
For Apache CXF versions 3.0.x before 3.0.1, update to version 3.0.1 or later.
Correção
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Cxf