Application plugins in Apache CXF Fediz prior to version 1.1.3 and 1.2.x prior to 1.2.1 allow remote attackers to create a denial of service.
| Score | Percentile |
|---|---|
| 13.56% | 93.62% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.5 | 3.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-3357-829x-m9pr ↗ |
| CVE | CVE-2015-5175 ↗ |
| CWE id | Name |
|---|---|
| CWE-20 | Improper Input Validation |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.apache.cxf.fediz:fediz-idp | < 1.1.3 | 1.1.3 | — |
| maven | org.apache.cxf.fediz:fediz-idp | >= 1.2, < 1.2.1 | 1.2.1 | — |
| maven | org.apache.cxf.fediz:fediz-core | < 1.1.3 | 1.1.3 | — |
| maven | org.apache.cxf.fediz:fediz-core | >= 1.2, < 1.2.1 | 1.2.1 | — |