Lucene search

K
cvelistApacheCVELIST:CVE-2019-17573
HistoryJan 16, 2020 - 5:50 p.m.

CVE-2019-17573

2020-01-1617:50:42
apache
www.cve.org
7

AI Score

6.1

Confidence

High

EPSS

0.006

Percentile

78.1%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CNA Affected

[
  {
    "product": "CXF",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "All versions of Apache CXF prior to 3.3.5 and 3.2.12."
      }
    ]
  }
]

References

AI Score

6.1

Confidence

High

EPSS

0.006

Percentile

78.1%