QID 980326

QID 980326: Java (maven) Security Update for org.apache.cxf:cxf (GHSA-64x2-gq24-75pv)

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-64x2-gq24-75pv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980326

    Software Advisories
    Advisory ID Software Component Link
    GHSA-64x2-gq24-75pv org.apache.cxf:apache-cxf URL Logo github.com/advisories/GHSA-64x2-gq24-75pv
    GHSA-64x2-gq24-75pv org.apache.cxf:cxf URL Logo github.com/advisories/GHSA-64x2-gq24-75pv