CVE-2014-3584: Medium severity apache cxf vulnerability
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3584?
CVE-2014-3584 is classified as a medium severity vulnerability due to its potential for triggering a denial of service condition.
How do I fix CVE-2014-3584?
To mitigate CVE-2014-3584, upgrade Apache CXF to versions 2.6.11, 2.7.8, or 3.0.1 or later.
Which versions of Apache CXF are affected by CVE-2014-3584?
Apache CXF versions before 2.6.11, 2.7.8, and 3.0.1 are vulnerable to CVE-2014-3584.
What type of attack does CVE-2014-3584 facilitate?
CVE-2014-3584 allows remote attackers to cause a denial of service through an infinite loop via a crafted SAML token in the authorization header.
Is CVE-2014-3584 easy to exploit?
Yes, CVE-2014-3584 can be easily exploited by sending specially crafted requests containing malicious SAML tokens.