An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.11CPE matchmatch criteria | cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.1.6CPE matchmatch criteria | cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:apache:cxf:4.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.