Loading HuntDB...

GHSA-6pff-fmh2-4mmf

GitHub Security Advisory

Apache CXF Denial of Service vulnerability in JOSE

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

Affected Packages

Maven org.apache.cxf:cxf-rt-rs-security-jose
Affected versions: 4.0.0 (fixed in 4.0.5)
Maven org.apache.cxf:cxf-rt-rs-security-jose
Affected versions: 3.6.0 (fixed in 3.6.4)
Maven org.apache.cxf:cxf-rt-rs-security-jose
Affected versions: 0 (fixed in 3.5.9)

Related CVEs

Key Information

GHSA ID
GHSA-6pff-fmh2-4mmf
Published
July 19, 2024 9:32 AM
Last Modified
July 19, 2024 6:34 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.cxf:cxf-rt-rs-security-jose
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.