Information Exposure Affecting org.apache.cxf:cxf-rt-transports-http package, versions [,3.4.10) [3.5.0,3.5.5)
Threat Intelligence
EPSS
0.09% (38th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHECXF-3168313
- published 14 Dec 2022
- disclosed 13 Dec 2022
- credit Beijin Qihoo 360 adlab
Introduced: 13 Dec 2022
CVE-2022-46363 Open this link in a new tabHow to fix?
Upgrade org.apache.cxf:cxf-rt-transports-http
to version 3.4.10, 3.5.5 or higher.
Overview
org.apache.cxf:cxf-rt-transports-http is an open source services framework.
Affected versions of this package are vulnerable to Information Exposure which allows an attacker to perform a remote directory listing or code exfiltration. Exploiting this vulnerability is possible when the CXF service is misconfigured.
NOTE
The vulnerability only applies when the CXFServlet is configured with both the static-resources-list
and redirect-query-check
attributes.
References
CVSS Scores
version 3.1