Description
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
No analysis available yet.
Remediation
Vendor Workaround
Users of Apache CXF should update to either 3.3.8 or 3.4.1. Alternatively, it is possible to disable the service listing altogether by setting the "hide-service-list-page" servlet parameter to "true".
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0770 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573. |
Github GHSA |
GHSA-64x2-gq24-75pv | Cross-site scripting in Apache CXF |
References
History
No history.
Subscriptions
Apache
Subscribe
Cxf
Subscribe
Netapp
Subscribe
Snap Creator Framework
Subscribe
Vasa Provider For Clustered Data Ontap
Subscribe
Oracle
Subscribe
Business Intelligence
Subscribe
Communications Messaging Server
Subscribe
Retail Order Broker Cloud Service
Subscribe
Redhat
Subscribe
Integration
Subscribe
Jboss Fuse
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:30.592Z
Reserved: 2020-06-08T00:00:00.000Z
Link: CVE-2020-13954
No data.
Status : Modified
Published: 2020-11-12T13:15:11.353
Modified: 2024-11-21T05:02:13.623
Link: CVE-2020-13954
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA