Apache cxf-core is vulnerable to denial of service (DoS) attacks. The attack can be triggered if the attacker sends a content-disposition
value containing more than 50000 characters, leading to high CPU usage in the application.
cxf.apache.org/security-advisories.data/CVE-2017-12624.txt.asc
www.securityfocus.com/bid/101859
www.securitytracker.com/id/1040486
access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/
access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/?version=7.1
access.redhat.com/errata/RHSA-2018:2423
access.redhat.com/errata/RHSA-2018:2424
access.redhat.com/errata/RHSA-2018:2425
access.redhat.com/errata/RHSA-2018:2428
access.redhat.com/security/updates/classification/#important
issues.jboss.org/browse/JBEAP-14788
lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E