CVE-2010-2076
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.79% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-829
- Affected
- apache/cxf
- Source
- secalert@redhat.com
References
- http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlVendor Advisory
- http://geronimo.apache.org/21x-security-report.htmlRelease Notes, Vendor Advisory
- http://geronimo.apache.org/22x-security-report.htmlRelease Notes, Vendor Advisory
- http://secunia.com/advisories/40969Broken Link, Vendor Advisory
- http://secunia.com/advisories/41016Broken Link, Vendor Advisory
- http://secunia.com/advisories/41025Broken Link, Vendor Advisory
- http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdfExploit, Vendor Advisory
- http://www.listware.net/201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.htmlBroken Link
- http://www.securityfocus.com/bid/42492Broken Link, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/GERONIMO-5383Third Party Advisory
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlVendor Advisory
- http://geronimo.apache.org/21x-security-report.htmlRelease Notes, Vendor Advisory
- http://geronimo.apache.org/22x-security-report.htmlRelease Notes, Vendor Advisory
- http://secunia.com/advisories/40969Broken Link, Vendor Advisory
- http://secunia.com/advisories/41016Broken Link, Vendor Advisory
- http://secunia.com/advisories/41025Broken Link, Vendor Advisory
- http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdfExploit, Vendor Advisory
- http://www.listware.net/201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.htmlBroken Link
- http://www.securityfocus.com/bid/42492Broken Link, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/GERONIMO-5383Third Party Advisory
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3EMailing List, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.