Reflected XSS Vulnerability in Apache CXF Services Page
CVE-2019-17573
6.1MEDIUM
Summary
Apache CXF, by default, generates a '/services' page that lists available endpoint names and addresses. This page is susceptible to reflected Cross-Site Scripting (XSS) attacks, enabling malicious actors to inject JavaScript code. Although this issue typically exploits a feature not found in contemporary browsers, mobile applications that access this page could be compromised. It is crucial for users and developers to apply security updates and implement measures to mitigate these risks.
Affected Version(s)
CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved