QID 982214

QID 982214: Java (maven) Security Update for org.apache.cxf:apache-cxf (GHSA-58p8-9g59-q2hr)

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-58p8-9g59-q2hr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982214

    Software Advisories
    Advisory ID Software Component Link
    GHSA-58p8-9g59-q2hr org.apache.cxf:apache-cxf URL Logo github.com/advisories/GHSA-58p8-9g59-q2hr
    GHSA-58p8-9g59-q2hr org.apache.cxf:cxf URL Logo github.com/advisories/GHSA-58p8-9g59-q2hr