Severity
7.5HIGH
EPSS
0.2%
top 54.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateApr 15

Description

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/cxf3.6.03.6.4+2
CVEListV5apache_software_foundation/apache_cxf< 4.0.5, 3.6.4, 3.5.9

🔴Vulnerability Details

3
GHSA
Apache CXF Denial of Service vulnerability in JOSE2024-07-19
OSV
Apache CXF Denial of Service vulnerability in JOSE2024-07-19
CVEList
Apache CXF Denial of Service vulnerability in JOSE2024-07-19

📋Vendor Advisories

3
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server, Client Installer (Apache CXF) — CVE-2024-320072025-04-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Apache CXF) — CVE-2024-320072024-10-15
Red Hat
apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE2024-07-19
CVE-2024-32007 (HIGH CVSS 7.5) | An improper input validation of the | cvebase.io