CVE-2024-32007
published 2024-07-19CVE-2024-32007: An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.27%
66.5th percentile
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.5.9 | 3.5.9 |
| apache | cxf | >= 3.6.0 < 3.6.4 | 3.6.4 |
| apache | cxf | >= 4.0.0 < 4.0.5 | 4.0.5 |
| apache_software_foundation | apache_cxf | < 4.0.5, 3.6.4, 3.5.9 | 4.0.5, 3.6.4, 3.5.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache CXF Denial of Service vulnerability in JOSE
ghsa·2024-07-19
CVE-2024-32007 [MEDIUM] CWE-20 Apache CXF Denial of Service vulnerability in JOSE
Apache CXF Denial of Service vulnerability in JOSE
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
OSV
Apache CXF Denial of Service vulnerability in JOSE
osv·2024-07-19
CVE-2024-32007 [MEDIUM] Apache CXF Denial of Service vulnerability in JOSE
Apache CXF Denial of Service vulnerability in JOSE
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server, Client Installer (Apache CXF) — CVE-2024-32007
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-32007 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Server, Client Installer (Apache CXF) — CVE-2024-32007
Oracle Oracle Analytics Risk Matrix: Analytics Server, Client Installer (Apache CXF) vulnerability
CVE: CVE-2024-32007
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Apache CXF) — CVE-2024-32007
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-32007 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Apache CXF) — CVE-2024-32007
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Apache CXF) vulnerability
CVE: CVE-2024-32007
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE
vendor_redhat·2024-07-19·CVSS 7.5
CVE-2024-32007 [HIGH] CWE-20 apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE
apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
An improper input validation vulnerability was found in the p2c parameter in the Apache CXF JOSE. This flaw allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Statement: The improper input validation vulnerability in the p2c parameter of Apache CXF JOSE is considered a moderate severity issue rather than a important one due to its limited scope and impact. While the flaw allows an attacker to specify a large val
Suricata
ET WEB_SPECIFIC_APPS Apache Spark OS Command Injection (CVE-2023-32007)
suricata·2024-09-26·CVSS 8.8
CVE-2023-32007 [HIGH] ET WEB_SPECIFIC_APPS Apache Spark OS Command Injection (CVE-2023-32007)
ET WEB_SPECIFIC_APPS Apache Spark OS Command Injection (CVE-2023-32007)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Apache Spark OS Command Injection (CVE-2023-32007)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/jobs/?doAs|3d|"; fast_pattern; startswith; pcre:"/^(?:\x3b|\x0a|\x26|\x60|\x7c|\x24)/R"; reference:url,mp.weixin.qq.com/s/jCvb9e_lPWLS01cjw2wqjw; reference:cve,2023-32007; classtype:web-application-attack; sid:2056206; rev:1; metadata:affected_product Apache_Spark, attack_target Server, tls_state TLSDecrypt, created_at 2024_09_26, cve CVE_2023_32007, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at 2024_09_26, mitre_tactic_id TA0001, mitre_t
No public exploits indexed.
2024-07-19
Published