imPC@ndo IT

Tracker / CVE-2020-13954

CVE-2020-13954

Medium 6.1

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Affected products and versions

apache cxf · … → 3.3.8
apache cxf · 3.4.0 → 3.4.1
netapp snap_creator_framework
netapp vasa_provider_for_clustered_data_ontap · 9.6 → …
oracle business_intelligence
oracle communications_messaging_server
oracle retail_order_broker_cloud_service

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References