Description
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0728 | Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count". |
Github GHSA |
GHSA-58p8-9g59-q2hr | Potential DOS attack due to unrestricted attachment count in messages |
References
History
No history.
Subscriptions
Apache
Subscribe
Cxf
Subscribe
Oracle
Subscribe
Commerce Guided Search
Subscribe
Flexcube Private Banking
Subscribe
Retail Order Broker
Subscribe
Redhat
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T23:17:40.123Z
Reserved: 2019-05-28T00:00:00.000Z
Link: CVE-2019-12406
No data.
Status : Modified
Published: 2019-11-06T21:15:11.180
Modified: 2024-11-21T04:22:46.487
Link: CVE-2019-12406
OpenCVE Enrichment
No data.
EUVD
Github GHSA