CVE-2017-12624
published 2017-11-14CVE-2017-12624: Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that…
PriorityP425medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
3.70%
88.5th percentile
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | >= 3.0.0 < 3.0.16 | 3.0.16 |
| apache | cxf | >= 3.1.0 < 3.1.14 | 3.1.14 |
| apache | cxf | >= 3.2.0 < 3.2.1 | 3.2.1 |
| apache_software_foundation | apache_cxf | — | — |
| apache_software_foundation | apache_cxf | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Input Validation in Apache CXF
ghsa·2022-05-13
CVE-2017-12624 [MEDIUM] CWE-20 Improper Input Validation in Apache CXF
Improper Input Validation in Apache CXF
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".
OSV
Improper Input Validation in Apache CXF
osv·2022-05-13
CVE-2017-12624 [MEDIUM] Improper Input Validation in Apache CXF
Improper Input Validation in Apache CXF
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".
Red Hat
cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
vendor_redhat·2017-11-14·CVSS 5.5
CVE-2017-12624 [MEDIUM] CWE-20 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".
Package: cxf (Red Hat BPM Suite 6) - Not affected
Package: cxf (Red Hat Fuse 7) - Affected
Package: cxf (Red Hat JBoss BRMS 5) - Not affected
Package: cxf (Red Hat JBoss BRMS 6) - Not affected
Package: c
No detection rules found.
No public exploits indexed.
arXiv
Multi-Granularity Detector for Vulnerability Fixes
arxiv_fulltext·2023-05-23
Multi-Granularity Detector for Vulnerability Fixes
Multi-Granularity Detector for Vulnerability Fixes
Truong Giang Nguyen,
Thanh Le-Cong,
Hong Jin Kang,
Ratnadira Widyasari,
Chengran Yang,
Zhipeng Zhao,
Bowen Xu,
Jiayuan Zhou,
Xin Xia,
Ahmed E. Hassan,
Xuan-Bach D. Le,
and David Lo
Truong Giang Nguyen, Thanh Le-Cong, Hong Jin Kang, Ratnadira Widyasari, Chengran Yang, Zhipeng Zhao, Bowen Xu, David Lo are with the School of Computing and Information Systems, Singapore Management University, Singapore.
E-mail:\gtnguyen, tlecong, hjkang.2018, ratnadiraw.2020, cryang, zpzhao, bowenxu.2017, davidlo\ @smu.edu.sg.
Jiayuan Zhou and Xin Xia are with the Software Engineering Application Technology Lab, Huawei, China.
E-mail: [email protected], [email protected]
Ahmed E. Hassan is with School of Computing, Queen's University, Canada
E-mail: a
Bugzilla
CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services [fedora-all]
bugzilla·2017-11-21·CVSS 5.5
CVE-2017-12624 [MEDIUM] CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services [fedora-all]
CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
bugzilla·2017-11-21·CVSS 5.5
CVE-2017-12624 [MEDIUM] CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
A flaw was found in Apache CXF prior to 3.2.1 and 3.1.14. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack.
Upstream patch:
https://github.com/apache/cxf/commit/8bd915bfd7735c248ad660059c6b6ad26cdbcdf6
References:
http://cxf.apache.org/security-advisories.data/CVE-2017-12624.txt.asc
Discussion:
Created cxf tracking bugs for this issue:
Affects: fedora-all [bug 1515977]
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:2425 https://access.redhat.com/errata/RHSA
http://cxf.apache.org/security-advisories.data/CVE-2017-12624.txt.aschttp://www.securityfocus.com/bid/101859http://www.securitytracker.com/id/1040486https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/security-advisories.data/CVE-2017-12624.txt.aschttp://www.securityfocus.com/bid/101859http://www.securitytracker.com/id/1040486https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2017-11-14
Published