A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3w37-5p3p-jv92 | Apache CXF vulnerable to Exposure of Sensitive Information |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 22 Apr 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-22T02:50:45.431Z
Reserved: 2022-12-02T08:07:29.876Z
Link: CVE-2022-46363
Updated: 2024-08-03T14:31:45.874Z
Status : Modified
Published: 2022-12-13T15:15:11.677
Modified: 2025-04-22T03:15:20.727
Link: CVE-2022-46363
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA