Vulnerabilities > Apache > CXF > 2.4.3

DATE CVE VULNERABILITY TITLE RISK
2017-08-10 CVE-2017-3156 Unspecified vulnerability in Apache CXF
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
network
low complexity
apache
7.5
2017-08-10 CVE-2016-8739 XXE vulnerability in Apache CXF
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders.
network
low complexity
apache CWE-611
7.5
2017-08-10 CVE-2016-6812 Cross-site Scripting vulnerability in Apache CXF
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints.
network
low complexity
apache CWE-79
6.1