Apache CXF是美国阿帕奇(Apache)基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。 Apache CXF 3.5.10、3.6.5和4.0.6之前版本存在资源管理错误漏洞,该漏洞源于容易受到拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 0 ~ 3.5.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-23195 | Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie | |
| CVE-2025-23196 | Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition | |
| CVE-2024-51941 | Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts | |
| CVE-2024-45478 | Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input | |
| CVE-2024-45479 | Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost |
No comments yet