CVE Database
/

CVE-2019-12406

Back to search

CVE-2019-12406

Published: Nov 6, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

VendorProductVersions

n/a

Apache CXF

affected
Apache CXF versions before 3.3.4 and 3.2.11

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now