216.73.216.6

CVE-2024-32007

· Published 19/07/2024 09:15 · Modified 19/07/2024 20:22

Labels: CVE-2024-32007 2024-07-19CVE-2024-32007CWE-20NVD-CWE-noinfo[email protected]

Essential information

Published
19/07/2024 09:15
Modified
19/07/2024 20:22
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apache / cxf cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
apache / cxf cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
apache / cxf cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

References