VDB

CVE-2016-8739

CVE-2016-8739 PUBLISHED

Reported by apache · Published August 10, 2017

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

Affected Products

VendorProductVersions
Apache Software FoundationApache CXFprior to 3.0.12, 3.1.x prior to 3.1.9
Apache Software FoundationApache CXF3.1.x prior to 3.1.9, 3.1.x prior to 3.1.9, prior to 3.0.12
Mavenorg.apache.cxf:cxf-core0, 0

Timeline

  • Aug 10, 2017 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›