cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
Published Nov 14, 2017
5.5
MEDIUMCVSS 3.0
EPSS 3.70%
Description
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".
Affected products
-
- Version 3.2.x prior to 3.2.1StatusaffectedConstraints-
- Version prior to 3.1.14StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | n/a |
|
No data.
Red Hat JBoss EAP 7.1
cxf
Fixed · RHSA-2018:2425
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat Single Sign-On 7.2.4 zip
cxf
Fixed · RHSA-2018:2428
Red Hat BPM Suite 6
cxf
Not affected
Red Hat Fuse 7
cxf
Affected
Red Hat JBoss BRMS 5
cxf
Not affected
Red Hat JBoss BRMS 6
cxf
Not affected
Red Hat JBoss Data Grid 6
cxf
Not affected
Red Hat JBoss Data Virtualization 6
cxf
Not affected
Red Hat JBoss Enterprise Application Platform 5
cxf
Will not fix
Red Hat JBoss Enterprise Application Platform 6
cxf
Will not fix
Red Hat JBoss Fuse 6
cxf
Affected
Red Hat JBoss Fuse Integration Service 2
cxf
Affected
Red Hat JBoss Fuse Service Works 6
cxf
Will not fix
Red Hat JBoss Operations Network 3
cxf
Not affected
Red Hat JBoss Portal 6
cxf
Not affected
Red Hat JBoss SOA Platform 5
cxf
Will not fix
Red Hat Single Sign-On 7
cxf
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss EAP 7.1 | cxf | Fixed | RHSA-2018:2425 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat Single Sign-On 7.2.4 zip | cxf | Fixed | RHSA-2018:2428 |
| Red Hat BPM Suite 6 | cxf | Not affected | n/a |
| Red Hat Fuse 7 | cxf | Affected | n/a |
| Red Hat JBoss BRMS 5 | cxf | Not affected | n/a |
| Red Hat JBoss BRMS 6 | cxf | Not affected | n/a |
| Red Hat JBoss Data Grid 6 | cxf | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | cxf | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | cxf | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | cxf | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | cxf | Affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | cxf | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | cxf | Will not fix | n/a |
| Red Hat JBoss Operations Network 3 | cxf | Not affected | n/a |
| Red Hat JBoss Portal 6 | cxf | Not affected | n/a |
| Red Hat JBoss SOA Platform 5 | cxf | Will not fix | n/a |
| Red Hat Single Sign-On 7 | cxf | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.70% (0.03697) | 89.38th | v5 (v2026.06.15) |
| Sep 22, 2026 | 3.70% (0.03697) | 89.23th | v5 (v2026.06.15) |
| Sep 21, 2026 | 7.53% (0.07529) | 94.32th | v5 (v2026.06.15) |
| Sep 6, 2026 | 3.70% (0.03697) | 88.99th | v5 (v2026.06.15) |
| Sep 5, 2026 | 7.53% (0.07529) | 94.19th | v5 (v2026.06.15) |
| Aug 30, 2026 | 3.70% (0.03697) | 88.93th | v5 (v2026.06.15) |
| Aug 28, 2026 | 7.53% (0.07529) | 94.15th | v5 (v2026.06.15) |
| Aug 24, 2026 | 3.70% (0.03697) | 88.87th | v5 (v2026.06.15) |
| Aug 23, 2026 | 7.53% (0.07529) | 94.13th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.70% (0.03697) | 88.26th | v5 (v2026.06.15) |
| Feb 1, 2026 | 3.57% (0.03566) | 87.47th | v4 (v2025.03.14) |
| Nov 10, 2025 | 5.41% (0.05408) | 89.68th | v4 (v2025.03.14) |
| Oct 26, 2025 | 4.06% (0.04062) | 88.00th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.30% (0.02297) | 83.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 38.59% (0.38591) | 95.84th | v4 (v2025.03.14) |
| Mar 28, 2025 | 2.30% (0.02297) | 83.27th | v4 (v2025.03.14) |
| Mar 27, 2025 | 38.59% (0.38591) | 96.74th | v4 (v2025.03.14) |
| Mar 20, 2025 | 17.10% (0.17100) | 94.50th | v4 (v2025.03.14) |
| Mar 19, 2025 | 38.59% (0.38591) | 96.80th | v4 (v2025.03.14) |
| Mar 17, 2025 | 17.10% (0.17100) | 94.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.20% (0.00202) | 59.10th | v3 (v2023.03.01) |
| Feb 18, 2024 | 0.20% (0.00202) | 57.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.16% (0.00164) | 51.19th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.65% (0.12652) | 95.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.65% (0.12652) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.65% (0.12652) | 90.03th | v2 (v2022.01.01) |
| Feb 3, 2022 | 34.65% (0.34654) | 97.76th | v1 |
| Sep 1, 2021 | 34.65% (0.34654) | 98.79th | v1 |
| Jun 17, 2021 | 34.65% (0.34654) | 0.00th | v1 |
| Apr 14, 2021 | 32.98% (0.32984) | 0.00th | v1 |
References (28)
- http://cxf.apache.org/security-advisories.data/CVE-2017-12624.txt.asc x_refsource_CONFIRMIssue TrackingVendor Advisory
- http://www.securityfocus.com/bid/101859 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040486 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2423 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:2424 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:2425 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:2428 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-12624 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1515976 Issue Tracking
- https://github.com/advisories/GHSA-7vgj-8mw4-hg8r Advisory
- https://github.com/apache/cxf/commit/896bd961cbbb6b8569700e5b70229f78f94ad9d
- https://github.com/apache/cxf/commit/8bd915bfd7735c248ad660059c6b6ad26cdbcdf6
- https://github.com/apache/cxf/commit/a2ce435cf0eedc8158d118d6d275114408d2a376
- https://issues.apache.org/jira/browse/CXF-7507
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2017-12624
- https://www.cve.org/CVERecord?id=CVE-2017-12624
Change history (0)
No recorded changes yet.