CVE-2019-17573

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-17573
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17573.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-17573
Aliases
Related
Published
2020-01-16T18:15:11Z
Modified
2024-09-03T02:29:53.403974Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

References

Affected packages

Git / github.com/apache/cxf

Affected ranges

Type
GIT
Repo
https://github.com/apache/cxf
Events

Affected versions

cxf-3.*

cxf-3.3.0
cxf-3.3.1
cxf-3.3.2
cxf-3.3.3
cxf-3.3.4