CVE-2020-13954
published 2020-11-12CVE-2020-13954: By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected…
PriorityP340medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
42.99%
98.6th percentile
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.3.8 | 3.3.8 |
| apache | cxf | >= 3.4.0 < 3.4.1 | 3.4.1 |
| netapp | vasa_provider_for_clustered_data_ontap | >= 9.6 | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | retail_order_broker_cloud_service | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site scripting in Apache CXF
osv·2021-04-22·CVSS 6.1
CVE-2020-13954 [MEDIUM] Cross-site scripting in Apache CXF
Cross-site scripting in Apache CXF
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
GHSA
Cross-site scripting in Apache CXF
ghsa·2021-04-22·CVSS 6.1
CVE-2020-13954 [MEDIUM] CWE-79 Cross-site scripting in Apache CXF
Cross-site scripting in Apache CXF
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Samples (Apache CXF) — CVE-2020-13954
vendor_oracle·2023-04-15·CVSS 6.1
CVE-2020-13954 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Samples (Apache CXF) — CVE-2020-13954
Oracle Oracle Fusion Middleware Risk Matrix: Samples (Apache CXF) vulnerability
CVE: CVE-2020-13954
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Message Store (Apache CXF) — CVE-2020-13954
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2020-13954 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Message Store (Apache CXF) — CVE-2020-13954
Oracle Oracle Communications Applications Risk Matrix: Message Store (Apache CXF) vulnerability
CVE: CVE-2020-13954
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Supplier Direct Fulfillment (Apache CXF) — CVE-2020-13954
vendor_oracle·2021-01-15·CVSS 6.1
CVE-2020-13954 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Supplier Direct Fulfillment (Apache CXF) — CVE-2020-13954
Oracle Oracle Retail Applications Risk Matrix: Supplier Direct Fulfillment (Apache CXF) vulnerability
CVE: CVE-2020-13954
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
cxf: XSS via the styleSheetPath
vendor_redhat·2020-11-12·CVSS 6.1
CVE-2020-13954 [MEDIUM] CWE-79 cxf: XSS via the styleSheetPath
cxf: XSS via the styleSheetPath
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Mitigation: Users can disable the service listing altogether by setting the "hide-service-list-page" servlet parameter to "true".
Package: cxf (Red Hat BPM Suite 6) - Out of support scope
Package: cxf-core (Red Hat BPM Suite 6) - Out of support scope
Package: cxf-core (Red Hat Decision Manager 7) - Affected
Package: cxf-core (Red Ha
No detection rules found.
No public exploits indexed.
http://cxf.apache.org/security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183670659&api=v2http://www.openwall.com/lists/oss-security/2020/11/12/2https://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cusers.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r640719c9ce5671f239a6f002c20e14062effe4b318a580b6746aa5ef%40%3Cdev.syncope.apache.org%3Ehttps://lists.apache.org/thread.html/r81a41a2915985d49bc3ea57dde2018b03584a863878a8532a89f993f%40%3Cusers.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210513-0010/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://cxf.apache.org/security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183670659&api=v2http://www.openwall.com/lists/oss-security/2020/11/12/2https://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r51fdd73548290b2dfd0b48f7ab69bf9ae064dd100364cd8a15f0b3ec%40%3Cusers.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r640719c9ce5671f239a6f002c20e14062effe4b318a580b6746aa5ef%40%3Cdev.syncope.apache.org%3Ehttps://lists.apache.org/thread.html/r81a41a2915985d49bc3ea57dde2018b03584a863878a8532a89f993f%40%3Cusers.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210513-0010/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-11-12
Published