CVE-2016-8739: XEE
Apache CXF JAX-RS implementation provides a number of Atom MessageBodyReaders. These readers use Apache Abdera Parser to parse Atom feeds or Entries, with this Parser expanding XML entities by default. This represents a major XXE risk.
External References:
http://cxf.apache.org/security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360575&api=v2
Other sources
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.cxf:cxf-coreto a version that resolves this vulnerability.Fixed in 3.1.9 - Upgrade
Upgrade
maven/org.apache.cxf:cxf-coreto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 3.1.9 - Upgrade
Upgrade
Apache CXF JAX-RS moduleto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
Apache CXF JAX-RS moduleto a version that resolves this vulnerability.Fixed in 3.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8739?
CVE-2016-8739 is classified as a major vulnerability due to its potential for XML External Entity (XXE) attacks.
How do I fix CVE-2016-8739?
To fix CVE-2016-8739, upgrade Apache CXF to version 3.1.9 or later, or to version 3.0.12 if you are on an older version.
Which versions of Apache CXF are affected by CVE-2016-8739?
CVE-2016-8739 affects Apache CXF versions up to and including 3.0.11 and versions 3.1.0 to 3.1.8.
What type of attacks does CVE-2016-8739 enable?
CVE-2016-8739 enables XML External Entity (XXE) attacks, which can result in data exposure or denial of service.
Is there a workaround for CVE-2016-8739 if I cannot upgrade?
There are no official workarounds for CVE-2016-8739, and upgrading to a patched version is the recommended approach.