imPC@ndo EN

Tracker / CVE-2020-13954

CVE-2020-13954

Media 6.1

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Prodotti e versioni affette

apache cxf · … → 3.3.8
apache cxf · 3.4.0 → 3.4.1
netapp snap_creator_framework
netapp vasa_provider_for_clustered_data_ontap · 9.6 → …
oracle business_intelligence
oracle communications_messaging_server
oracle retail_order_broker_cloud_service

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti