Tracker / CVE-2020-13954
CVE-2020-13954
Media 6.1
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Prodotti e versioni affette
| apache | cxf · … → 3.3.8 |
|---|---|
| apache | cxf · 3.4.0 → 3.4.1 |
| netapp | snap_creator_framework |
| netapp | vasa_provider_for_clustered_data_ontap · 9.6 → … |
| oracle | business_intelligence |
| oracle | communications_messaging_server |
| oracle | retail_order_broker_cloud_service |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.