Reflected XSS Vulnerability in Apache CXF Services Page
CVE-2019-17573

6.1MEDIUM

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
16 January 2020

Summary

Apache CXF, by default, generates a '/services' page that lists available endpoint names and addresses. This page is susceptible to reflected Cross-Site Scripting (XSS) attacks, enabling malicious actors to inject JavaScript code. Although this issue typically exploits a feature not found in contemporary browsers, mobile applications that access this page could be compromised. It is crucial for users and developers to apply security updates and implement measures to mitigate these risks.

Affected Version(s)

CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.