Cross-site Tracing (XST) Affecting org.apache.cxf:cxf-rt-transports-http-jetty package, versions [3.0.0,3.0.12)[3.1.0,3.1.9)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Tracing (XST) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHECXF-30583
  • published30 Oct 2016
  • disclosed30 Oct 2016
  • creditUnknown

Introduced: 30 Oct 2016

CVE NOT AVAILABLE CWE-284  (opens in a new tab)

Overview

org.apache.cxf:cxf-rt-transports-http-jetty is an open source services framework.

Affected versions of the package are vulnerable to Cross-site Tracing (XST). The package still had HTTP TRACE method enabled. It is considered as a security risk.

CVSS Base Scores

version 3.1