Codehaus is an open-source collective that produced XFire, a lightweight SOAP web-services framework for Java that saw use in enterprise messaging and service-oriented architecture implementations. The durable signal in its vulnerability profile centers on certificate validation weaknesses, reflecting the security-critical role that transport-layer trust mechanisms play in web-services integration. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codehaus over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5817HIGH Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject | Nov 4, 2012 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codehaus.
Media articles that mention a CVE ID that affects a product developed by Codehaus — matched by CVE ID, not by vendor name.