Reflected XSS Vulnerability in Apache CXF Services Page
CVE-2019-17573
What is CVE-2019-17573?
Apache CXF, by default, generates a '/services' page that lists available endpoint names and addresses. This page is susceptible to reflected Cross-Site Scripting (XSS) attacks, enabling malicious actors to inject JavaScript code. Although this issue typically exploits a feature not found in contemporary browsers, mobile applications that access this page could be compromised. It is crucial for users and developers to apply security updates and implement measures to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved