Missing XML Validation in Apache CXF
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 2.5.0, < 2.5.10
>= 2.6.0, < 2.6.7
>= 2.7.0, < 2.7.4
Patched versions
2.5.10
2.6.7
2.7.4
Description
Published by the National Vulnerability Database
Aug 19, 2013
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 8, 2022
Last updated
Jan 27, 2023
The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.
References