org.apache.cxf:cxf-rt-transports-http@3.3.7 vulnerabilities

  • latest version

    4.1.0

  • latest non vulnerable version

  • first published

    16 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.cxf:cxf-rt-transports-http package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Information Exposure

    org.apache.cxf:cxf-rt-transports-http is an open source services framework.

    Affected versions of this package are vulnerable to Information Exposure which allows an attacker to perform a remote directory listing or code exfiltration. Exploiting this vulnerability is possible when the CXF service is misconfigured.

    NOTE The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes.

    How to fix Information Exposure?

    Upgrade org.apache.cxf:cxf-rt-transports-http to version 3.4.10, 3.5.5 or higher.

    [,3.4.10)[3.5.0,3.5.5)
    • H
    Cross-site Scripting (XSS)

    org.apache.cxf:cxf-rt-transports-http is an open source services framework.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the /services page, via the styleSheetPath, which allows a malicious actor to inject Javascript into the web page. This is a separate issue to CVE-2019-17573.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.apache.cxf:cxf-rt-transports-http to version 3.3.8, 3.4.1 or higher.

    [,3.3.8)[3.4.0,3.4.1)