← volver
CVE-2020-13954

Apache CXF Reflected XSS in the services listing page via the styleSheetPath

EPSS 43.0%CWE-79
Vexday Risk Score
15Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 43.0%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
12 nov 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →