Advisories for Maven/Org.apache.cxf.services/Cxf-Services package

2017

Denial of Service attacks

This package supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack.