Vulnerabilities
Vulnerable Software
Apache:  >> Cxf  >> 3.4.4  Security Vulnerabilities
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
CVSS Score
7.5
EPSS Score
0.012
Published
2022-12-13
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
CVSS Score
7.5
EPSS Score
0.074
Published
2021-09-19


Contact Us

Shodan ® - All rights reserved