apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*
Published Jul 2, 2018
8.1
HIGHCVSS 3.0
EPSS 8.51%
Description
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.
Affected products
-
- Version 3.2.x prior to 3.2.5StatusaffectedConstraints-
- Version prior to 3.1.16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | n/a |
|
No data.
Red Hat Fuse 7.2
cxf-core
Fixed · RHSA-2018:3768
Red Hat JBoss A-MQ 6.3
cxf-core
Fixed · RHSA-2018:3817
Red Hat JBoss EAP 7.1
n/a
Fixed · RHSA-2018:2277
Red Hat JBoss EAP 7.1
cxf-core
Fixed · RHSA-2018:2425
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el6
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:2423
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el6
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el7
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:2424
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2276
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el7
Fixed · RHSA-2018:2276
Red Hat JBoss Fuse 6.3
cxf-core
Fixed · RHSA-2018:3817
Red Hat Single Sign-On 7.2
cxf-core
Fixed · RHSA-2018:2279
Red Hat Single Sign-On 7.2.4 zip
cxf-core
Fixed · RHSA-2018:2428
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
rhvm-appliance-0:4.2-20180828.0.el7
Fixed · RHSA-2018:2643
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Red Hat BPM Suite 6
cxf-core
Not affected
Red Hat JBoss BRMS 6
cxf
Not affected
Red Hat JBoss Data Virtualization 6
cxf-core
Not affected
Red Hat JBoss Enterprise Application Platform 6
cxf-core
Not affected
Red Hat OpenShift Application Runtimes
cxf-core
Affected
Red Hat Single Sign-On 7
cxf-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.2 | cxf-core | Fixed | RHSA-2018:3768 |
| Red Hat JBoss A-MQ 6.3 | cxf-core | Fixed | RHSA-2018:3817 |
| Red Hat JBoss EAP 7.1 | n/a | Fixed | RHSA-2018:2277 |
| Red Hat JBoss EAP 7.1 | cxf-core | Fixed | RHSA-2018:2425 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el6 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2423 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el6 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el7 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2424 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el7 | Fixed | RHSA-2018:2276 |
| Red Hat JBoss Fuse 6.3 | cxf-core | Fixed | RHSA-2018:3817 |
| Red Hat Single Sign-On 7.2 | cxf-core | Fixed | RHSA-2018:2279 |
| Red Hat Single Sign-On 7.2.4 zip | cxf-core | Fixed | RHSA-2018:2428 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhvm-appliance-0:4.2-20180828.0.el7 | Fixed | RHSA-2018:2643 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Red Hat BPM Suite 6 | cxf-core | Not affected | n/a |
| Red Hat JBoss BRMS 6 | cxf | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | cxf-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | cxf-core | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | cxf-core | Affected | n/a |
| Red Hat Single Sign-On 7 | cxf-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In OpenShift Logging the openshift-logging/elasticsearch6-rhel8 container bundles the vulnerable version of apache-cxf, but the vulnerable class is not shipped, hence this component is not affected by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (29 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.51% (0.08507) | 94.88th | v5 (v2026.06.15) |
| Sep 5, 2026 | 9.31% (0.09311) | 95.10th | v5 (v2026.06.15) |
| Aug 30, 2026 | 10.35% (0.10348) | 95.38th | v5 (v2026.06.15) |
| Aug 28, 2026 | 9.31% (0.09311) | 95.08th | v5 (v2026.06.15) |
| Aug 24, 2026 | 10.35% (0.10348) | 95.35th | v5 (v2026.06.15) |
| Aug 23, 2026 | 9.31% (0.09311) | 95.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 10.39% (0.10394) | 95.12th | v5 (v2026.06.15) |
| Nov 21, 2025 | 2.77% (0.02771) | 85.54th | v4 (v2025.03.14) |
| Nov 18, 2025 | 10.44% (0.10438) | 92.47th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.95% (0.01947) | 81.82th | v4 (v2025.03.14) |
| Mar 29, 2025 | 28.04% (0.28040) | 94.40th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.95% (0.01947) | 81.83th | v4 (v2025.03.14) |
| Mar 27, 2025 | 28.04% (0.28040) | 95.79th | v4 (v2025.03.14) |
| Mar 20, 2025 | 6.21% (0.06215) | 90.04th | v4 (v2025.03.14) |
| Mar 19, 2025 | 28.04% (0.28040) | 95.87th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.21% (0.06215) | 90.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.69% (0.00686) | 80.73th | v3 (v2023.03.01) |
| Feb 15, 2024 | 0.74% (0.00739) | 80.28th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.79% (0.00787) | 79.38th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.76% (0.00763) | 78.75th | v3 (v2023.03.01) |
| Jun 26, 2023 | 0.73% (0.00729) | 78.10th | v3 (v2023.03.01) |
| May 8, 2023 | 0.77% (0.00774) | 78.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.10% (0.01104) | 82.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 35.69% (0.35688) | 97.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 35.69% (0.35688) | 96.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 41.78% (0.41782) | 98.68th | v1 |
| Sep 1, 2021 | 41.78% (0.41782) | 99.32th | v1 |
| Jun 17, 2021 | 41.78% (0.41782) | 0.00th | v1 |
| Apr 14, 2021 | 40.79% (0.40786) | 0.00th | v1 |
References (38)
- http://cxf.apache.org/security-advisories.data/CVE-2018-8039.txt.asc?version=1&modificationDate=1530184663000&api=v2 x_refsource_CONFIRMMailing ListVendor Advisory
- http://www.securityfocus.com/bid/106357 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1041199 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2276 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2277 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2279 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2423 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2424 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2425 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2428 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2643 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3768 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:3817 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-8039 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1595332 Issue Tracking
- https://cxf.apache.org/security-advisories.data/CVE-2018-8039.txt.asc
- https://github.com/advisories/GHSA-jc7r-v6fg-2gpf Advisory
- https://github.com/apache/cxf/commit/8ed6208f987ff72e4c4d2cf8a6b1ec9b27575d4
- https://github.com/apache/cxf/commit/fae6fabf9bd7647f5e9cb68897a7d72b545b741b x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.apache.org/thread.html/1f8ff31df204ad0374ab26ad333169e0387a5e7ec92422f337431866%40%3Cdev.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/1f8ff31df204ad0374ab26ad333169e0387a5e7ec92422f337431866@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-8039
- https://www.cve.org/CVERecord?id=CVE-2018-8039
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISC
Change history (0)
No recorded changes yet.