CVE-2014-3584
published 2014-10-30CVE-2014-3584: The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.18%
93.6th percentile
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | <= 2.6.10 | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Loop with Unreachable Exit Condition in Apache CXF
ghsa·2022-05-13
CVE-2014-3584 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition in Apache CXF
Loop with Unreachable Exit Condition in Apache CXF
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
OSV
Loop with Unreachable Exit Condition in Apache CXF
osv·2022-05-13
CVE-2014-3584 [MEDIUM] Loop with Unreachable Exit Condition in Apache CXF
Loop with Unreachable Exit Condition in Apache CXF
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
Red Hat
CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
vendor_redhat·2014-10-25·CVSS 5.0
CVE-2014-3584 [MEDIUM] CWE-130 CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
Statement: This issue did not affect Apache CXF as shipped with Red Hat JBoss Enterprise Application Platform 5 and 6; Red Hat JBoss Enterprise Web Platform 5; Red Hat JBoss SOA Platform 5; Red Hat JBoss Fuse Service Works 6; Red Hat JBoss BRMS 5 and 6; Red Hat JBoss BPM Suite 6; Red Hat JBoss Data Virtualization 6; Red Hat JBoss Operations Network 3 and Red Hat JBoss Portal Platform 6 as the REST Web Services endpoints are not available.
Fuse ESB Enterprise 7 is now in Maintenance
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3584 Apache CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
bugzilla·2014-10-27·CVSS 5.0
CVE-2014-3584 [MEDIUM] CVE-2014-3584 Apache CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
CVE-2014-3584 Apache CXF: Denial of Service (DoS) via invalid JAX-RS SAML tokens
It was discovered that Apache CXF JAX-RS services, via the SamlHeaderInHandler implementation, incorrectly handled invalid SAML tokens provided in authorization headers of requests. A remote attacker can trigger an infinite loop by providing specially crafted values in authorization headers leading to a Denial of Service attack.
Upstream Issues:
https://issues.apache.org/jira/browse/CXF-5390
Upstream Commits:
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=0b3894f57388b9955f2c33b2295223f2835cd7b3
References:
http://cxf.apache.org/security-advisories.data/CVE-2014-3584.txt.asc
Discussion:
Created cxf tracking bugs for this issue:
Affects: fedora-all [bug 1157305]
---
Statement:
This is
Bugzilla
CVE-2014-3584 CVE-2014-3623 cxf: various flaws [fedora-all]
bugzilla·2014-10-27·CVSS 5.0
CVE-2014-3584 [MEDIUM] CVE-2014-3584 CVE-2014-3623 cxf: various flaws [fedora-all]
CVE-2014-3584 CVE-2014-3623 cxf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2014-3623 wildfly: various flaws [fedora-all]
bugzilla·2014-10-27·CVSS 5.0
CVE-2014-3623 [MEDIUM] CVE-2014-3623 wildfly: various flaws [fedora-all]
CVE-2014-3623 wildfly: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one track
http://cxf.apache.org/security-advisories.data/CVE-2014-3584.txt.aschttp://seclists.org/oss-sec/2014/q4/437http://secunia.com/advisories/61909http://www.securityfocus.com/bid/70738https://exchange.xforce.ibmcloud.com/vulnerabilities/97753https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/security-advisories.data/CVE-2014-3584.txt.aschttp://seclists.org/oss-sec/2014/q4/437http://secunia.com/advisories/61909http://www.securityfocus.com/bid/70738https://exchange.xforce.ibmcloud.com/vulnerabilities/97753https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2014-10-30
Published