漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache CXF directory listing / code exfiltration
Vulnerability Description
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apache CXF 输入验证错误漏洞
Vulnerability Description
Apache CXF是美国阿帕奇(Apache)基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。 Apache CXF 3.5.5和3.4.10之前版本存在输入验证错误漏洞,该漏洞源于允许攻击者执行远程目录列表或代码渗漏。
CVSS Information
N/A
Vulnerability Type
N/A