Apache CXF JOSE Vulnerability: Denial of Service Attack via Improper Input Validation
CVE-2024-32007

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
19 July 2024

Summary

An improper input validation vulnerability exists in the Apache CXF JOSE component, specifically related to the processing of the p2c parameter. This issue can be exploited by attackers who input excessively large values within tokens, potentially leading to a denial of service situation. Versions prior to 4.0.5, 3.6.4, and 3.5.9 are notably susceptible, allowing unauthorized access to resources through the manipulation of input parameters. It is crucial for users of affected versions to patch their installations promptly to mitigate the threat.

Affected Version(s)

Apache CXF 0 < 4.0.5, 3.6.4, 3.5.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jingcheng Yang and Jianjun Chen from Sichuan University and Zhongguancun Lab.
.