Tracker / CVE-2020-13954
CVE-2020-13954
Medium 6.1
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Affected products and versions
| apache | cxf · … → 3.3.8 |
|---|---|
| apache | cxf · 3.4.0 → 3.4.1 |
| netapp | snap_creator_framework |
| netapp | vasa_provider_for_clustered_data_ontap · 9.6 → … |
| oracle | business_intelligence |
| oracle | communications_messaging_server |
| oracle | retail_order_broker_cloud_service |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.