Skip to main content

Vendor/product archive

apache / cxf_fediz CVEs

Beta · best-effort

6 CVEs tagged to apache / cxf_fediz1 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2018-8038

Published Jul 5, 2018

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12631

Published Nov 30, 2017

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been foun…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5175

Published Jun 7, 2017

Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7662

Published May 16, 2017

Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7661

Published May 16, 2017

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been foun…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4464

Published Sep 21, 2016

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might al…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1