CVE-2019-12406
Published: Nov 6, 2019
Modified: Aug 4, 2024
Description
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
| Vendor | Product | Versions |
|---|---|---|
n/a | Apache CXF | affected Apache CXF versions before 3.3.4 and 3.2.11 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now