Bug 1406810 (CVE-2016-6812)
Summary: | CVE-2016-6812 apache-cxf: XSS in Apache CXF FormattedServiceListWriter | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abhgupta, aileenc, alazarot, aszczucz, bbaranow, bdawidow, bmaxwell, cdewolf, chazlett, csutherl, dandread, darran.lofthouse, dmcphers, dosoudil, drieden, epp-bugs, etirelli, fnasser, gvarsami, huwang, jason.greene, jawilson, jboss-set, jcoleman, jdg-bugs, jialiu, jokerman, jolee, jpallich, jshepherd, kverlaen, ldimaggi, lgao, lmeyer, mbaluch, mmccomas, mweiler, mwinkler, myarboro, nwallace, pdrozd, pslavice, puntogil, rnetuka, rrajasek, rsvoboda, rwagner, rzhang, soa-p-jira, sthorger, tcunning, theute, tiwillia, tkirby, ttarrant, twalsh, vtunka |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | apache-cxf 3.0.12, apache-cxf 3.1.9 | Doc Type: | If docs needed, set a value |
Doc Text: |
A vulnerability was found in FormattedServiceListWriter in Apache CXF HTTP transport module that could allow an attacker to inject unexpected matrix parameters into the request URL. On a successful injection these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-21 11:48:47 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1406813 | ||
Bug Blocks: | 1406817 |
Description
Andrej Nemec
2016-12-21 14:32:08 UTC
Created cxf tracking bugs for this issue: Affects: fedora-all [bug 1406813] By default the FormattedServiceListWriter is not used for listing JAX-WS webservices deployed to JBoss EAP 7, using the 'services/' uri path. marking EAP 7 as not affected. Same thing for EAP 6, FormattedServicesListWriter is not used. Marking EAP 6 as not affected. There are no running Web Services on the JON 3 Server. Marking it as not affected. CLI Command used to confirm can be found in: https://access.redhat.com/solutions/1300433 This issue has been addressed in the following products: Via RHSA-2017:0868 https://access.redhat.com/errata/RHSA-2017:0868 JPP ships the offending class, but is in reduced security support (C/I). Marking it as wontfix. JDG-6 ships, but is out of security support. Marking it as wontfix. This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2017:0868 https://access.redhat.com/errata/RHSA-2017:0868 |