Lucene search

K
cvelistApacheCVELIST:CVE-2020-13954
HistoryNov 12, 2020 - 12:45 p.m.

CVE-2020-13954 Apache CXF Reflected XSS in the services listing page via the styleSheetPath

2020-11-1212:45:14
CWE-79
apache
www.cve.org
1

7 High

AI Score

Confidence

High

0.178 Low

EPSS

Percentile

96.2%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

CNA Affected

[
  {
    "product": "Apache CXF",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "3.4.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "3.3.8",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

References

7 High

AI Score

Confidence

High

0.178 Low

EPSS

Percentile

96.2%