CVE Vulnerabilities

CVE-2014-3584

Published: Oct 30, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

Affected Software

NameVendorStart VersionEnd Version
CxfApache*2.6.10 (including)
CxfApache2.6.1 (including)2.6.1 (including)
CxfApache2.7.0 (including)2.7.0 (including)
CxfApache2.7.1 (including)2.7.1 (including)
CxfApache2.7.2 (including)2.7.2 (including)
CxfApache2.7.3 (including)2.7.3 (including)
CxfApache2.7.4 (including)2.7.4 (including)
CxfApache2.7.5 (including)2.7.5 (including)
CxfApache2.7.6 (including)2.7.6 (including)
CxfApache2.7.7 (including)2.7.7 (including)
CxfApache3.0.0 (including)3.0.0 (including)
Red Hat JBoss Fuse 6.1RedHat*

References