Apache / Cxf Fediz
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-8038 | Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the ap… | HIGH | 7.5 | Jul 5, 2018 |
| CVE-2017-12631 | Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnera… | HIGH | 8.8 | Nov 30, 2017 |
| CVE-2015-5175 | Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. | HIGH | 7.5 | Jun 7, 2017 |
| CVE-2017-7662 | Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to… | HIGH | 8.8 | May 16, 2017 |
| CVE-2017-7661 | Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnera… | HIGH | 8.8 | May 16, 2017 |
| CVE-2016-4464 | The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience… | CRITICAL | 9.8 | Sep 21, 2016 |
Showing 1 to 6 of 6 CVEs