By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.cxf:apache-cxf(Maven) | 0 | 3.2.12 | N/A |
| org.apache.cxf:apache-cxf(Maven) | 3.3.0 | 3.3.5 | N/A |
| org.apache.cxf:cxf(Maven) | 0 | 3.2.12 | N/A |
| org.apache.cxf:cxf(Maven) | 3.3.0 | 3.3.5 | N/A |
CVSS Metrics