Lucene search

K
githubGitHub Advisory DatabaseGHSA-X7XF-253V-X3W8
HistoryMay 13, 2022 - 1:09 a.m.

Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS

2022-05-1301:09:20
CWE-611
GitHub Advisory Database
github.com
15
apache cxf
jax-rs
xxe risk
atom jax-rs
apache abdera parser
xml entities

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.006

Percentile

77.6%

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

Affected configurations

Vulners
Node
org.apache.cxfcxf-coreRange3.1.03.1.8
OR
org.apache.cxfcxf-coreRange3.0.11
VendorProductVersionCPE
org.apache.cxfcxf-core*cpe:2.3:a:org.apache.cxf:cxf-core:*:*:*:*:*:*:*:*

References

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.006

Percentile

77.6%