CVE-2010-2076: Input Validation
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdlfirstpurexml, a similar issue to CVE-2010-1632.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2076?
CVE-2010-2076 is rated as a medium severity vulnerability due to its potential for file disclosure.
How do I fix CVE-2010-2076?
To fix CVE-2010-2076, update Apache CXF to version 2.0.13 or higher, 2.1.10 or higher, or 2.2.9 or higher.
Which versions are affected by CVE-2010-2076?
CVE-2010-2076 affects Apache CXF versions prior to 2.0.13, 2.1.10, and 2.2.9.
What kind of attacks can exploit CVE-2010-2076?
CVE-2010-2076 can be exploited by attackers to read arbitrary files through improper DTD rejection in SOAP messages.
Is there a way to mitigate CVE-2010-2076 without upgrading?
There are no recommended mitigations for CVE-2010-2076 apart from upgrading to the patched versions.