Man-in-the-Middle Vulnerability in Apache CXF JMX Integration
CVE-2020-1954
What is CVE-2020-1954?
Apache CXF, a popular framework for building web services, can be exploited when the 'createMBServerConnectorFactory' property of the default InstrumentationManagerImpl is enabled. This vulnerability allows attackers on the same host to carry out a man-in-the-middle attack, where they can connect to the JMX registry and redirect communication to a malicious server. Consequently, sensitive information sent and received over JMX could be compromised as the attacker acts as a proxy, intercepting data streams.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache CXF affects all versions prior to 3.3.6 and 3.2.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved