CVE-2014-3584

Aliases:GHSA-gw5j-77f9-v2g2
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 30 Oct 2014, 14:00
Last modified:06 Aug 2024, 10:50

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
5.59% LOW
6% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Oct 2014, 14:00
Published
Vulnerability first disclosed
06 Aug 2024, 10:50
Last Modified
Vulnerability information updated

Description

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 5.59% Percentile: 90%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • apachecxf

    ≤ 2.6.10 | 2.6.1 | 2.7.0 | 2.7.1 | 2.7.2 | 2.7.3 | 2.7.4 | 2.7.5 | 2.7.6 | 2.7.7 | 3.0.0

  • org.apache.cxfcxf-rt-frontend-jaxrs

    ≥ 2.5.0, < 2.6.11 | ≥ 2.7.0, < 2.7.8 | ≥ 3.0.0, < 3.0.1

References (22)