CVE-2016-8739
published 2017-08-10CVE-2016-8739: The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
7.32%
93.7th percentile
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | <= 3.0.11 | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache_software_foundation | apache_cxf | — | — |
| apache_software_foundation | apache_cxf | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
vendor_redhat·2016-12-19·CVSS 7.5
CVE-2016-8739 [HIGH] CWE-611 apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
Apache CXF JAX-RS implementation provides a number of Atom MessageBodyReaders. These readers use Apache Abdera Parser to parse Atom feeds or Entries, with this Parser expanding XML entities by default. It was found that this represents a major XXE risk.
Package: cxf (Red Hat BPM Suite 6) - Not affected
Package: cxf (Red Hat JBoss BRMS 5) - Will not fix
Package: cxf (Red Hat JBoss BRMS 6) - Not affected
Package: cxf (Red Hat JBoss Data Grid 6) - Not affected
Package: cxf (Red
OSV
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
osv·2022-05-13
CVE-2016-8739 [HIGH] Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
GHSA
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
ghsa·2022-05-13
CVE-2016-8739 [HIGH] CWE-611 Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6812 CVE-2016-8739 cxf: various flaws [fedora-all]
bugzilla·2016-12-21·CVSS 6.1
CVE-2016-6812 [MEDIUM] CVE-2016-6812 CVE-2016-8739 cxf: various flaws [fedora-all]
CVE-2016-6812 CVE-2016-8739 cxf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2016-8739 apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
bugzilla·2016-12-21·CVSS 7.5
CVE-2016-8739 [HIGH] CVE-2016-8739 apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
CVE-2016-8739 apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE
Apache CXF JAX-RS implementation provides a number of Atom MessageBodyReaders. These readers use Apache Abdera Parser to parse Atom feeds or Entries, with this Parser expanding XML entities by default. This represents a major XXE risk.
External References:
http://cxf.apache.org/security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360575&api=v2
Discussion:
Created cxf tracking bugs for this issue:
Affects: fedora-all [bug 1406813]
---
JBoss EAP 6 and 7 implement JAX-RS using Resteasy, not CXF. Therefore the vulnerable AbstractAtomProvider class is not part of either distribution. Setting EAP 6 and 7 layered productgs as not affected.
---
This issue has been addresse
http://cxf.apache.org/security-advisories.data/CVE-2016-8739.txt.aschttp://www.securityfocus.com/bid/97579http://www.securitytracker.com/id/1037544https://access.redhat.com/errata/RHSA-2017:0868https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/security-advisories.data/CVE-2016-8739.txt.aschttp://www.securityfocus.com/bid/97579http://www.securitytracker.com/id/1037544https://access.redhat.com/errata/RHSA-2017:0868https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2017-08-10
Published