-
CVSS Score
-The vulnerability stems from unvalidated processing of XOP:Include href attributes during MTOM request handling. Key functions would be those responsible for:
While exact patch details aren't available, the advisory explicitly identifies MTOM/XOP href processing as the vulnerability vector. These functions are core to CXF's attachment handling and would appear in stack traces when processing malicious XOP:Include elements. The medium confidence reflects inference from vulnerability patterns in MTOM processing rather than direct patch analysis.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.cxf:cxf-core | maven | < 3.4.10 | 3.4.10 |
| org.apache.cxf:cxf-core | maven | >= 3.5.0, < 3.5.5 | 3.5.5 |
Ongoing coverage of React2Shell