QID 982221
QID 982221: Java (maven) Security Update for org.apache.cxf.fediz:fediz-jetty9 (GHSA-w3gh-g32m-cvhr)
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w3gh-g32m-cvhr for updates pertaining to this vulnerability.
Vendor References
- GHSA-w3gh-g32m-cvhr -
github.com/advisories/GHSA-w3gh-g32m-cvhr
CVEs related to QID 982221
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w3gh-g32m-cvhr | org.apache.cxf.fediz:fediz-jetty8 |
|
|
| GHSA-w3gh-g32m-cvhr | org.apache.cxf.fediz:fediz-jetty9 |
|
|
| GHSA-w3gh-g32m-cvhr | org.apache.cxf.fediz:fediz-spring |
|
|
| GHSA-w3gh-g32m-cvhr | org.apache.cxf.fediz:fediz-spring2 |
|
|
| GHSA-w3gh-g32m-cvhr | org.apache.cxf.fediz:fediz-spring3 |
|