CVE Vulnerabilities

CVE-2014-3584

Published: Oct 30, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 2.6.10 (including)
Cxf Apache 2.6.1 (including) 2.6.1 (including)
Cxf Apache 2.7.0 (including) 2.7.0 (including)
Cxf Apache 2.7.1 (including) 2.7.1 (including)
Cxf Apache 2.7.2 (including) 2.7.2 (including)
Cxf Apache 2.7.3 (including) 2.7.3 (including)
Cxf Apache 2.7.4 (including) 2.7.4 (including)
Cxf Apache 2.7.5 (including) 2.7.5 (including)
Cxf Apache 2.7.6 (including) 2.7.6 (including)
Cxf Apache 2.7.7 (including) 2.7.7 (including)
Cxf Apache 3.0.0 (including) 3.0.0 (including)
Red Hat JBoss Fuse 6.1 RedHat *

References