CVE-2017-12624

MEDIUM

Apache Cxf < 3.0.16 - Denial of Service

Title source: rule

Description

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

Exploits (1)

nomisec STUB
by tafamace · poc
https://github.com/tafamace/CVE-2017-12624

Scores

CVSS v3 5.5
EPSS 0.0357
EPSS Percentile 87.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

Status published
Products (4)
apache/cxf 3.0.0 - 3.0.16
Apache Software Foundation/Apache CXF 3.2.x prior to 3.2.1
Apache Software Foundation/Apache CXF prior to 3.1.14
org.apache.cxf/cxf-core 3.2.0 - 3.2.1Maven
Published Nov 14, 2017
Tracked Since Feb 18, 2026