Geronimo
  1. Geronimo
  2. GERONIMO-5383

CVE-2010-1632 and CVE-2010-2076: Axis2 and CXF HTTP binding enables DTD based XML attacks.

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Critical Critical
    • Resolution: Fixed
    • Affects Version/s: 2.1.5, 2.2
    • Fix Version/s: 2.1.6, 2.2.1
    • Component/s: webservices
    • Security Level: public (Regular issues)
    • Labels:
      None

      Description

      New versions of CXF and Axis2 are available containing some critical security fixes that need to be made available for Geronimo 2.1.x and 2.2.x. Details of the exposure can be found here:

      https://svn.apache.org/repos/asf/axis/axis2/java/core/security/CVE-2010-1632.pdf
      https://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf

        Activity

        Shawn Jiang made changes -
        Status Open [ 1 ] Closed [ 6 ]
        Resolution Fixed [ 1 ]
        Rick McGuire made changes -
        Fix Version/s 2.1.6 [ 12314972 ]
        Fix Version/s 2.1.7 [ 12315142 ]
        Rick McGuire made changes -
        Fix Version/s 2.1.7 [ 12315142 ]
        Fix Version/s 2.1.6 [ 12314972 ]
        Rick McGuire made changes -
        Field Original Value New Value
        Summary Update to new versions of CXF and Axis2 CVE-2010-1632 and CVE-2010-2076: Axis2 and CXF HTTP binding enables DTD based XML attacks.
        Priority Major [ 3 ] Critical [ 2 ]
        Description New versions of CXF and Axis2 are available containing some critical fixes that need to be made available for Geronimo 2.1.x and 2.2.x New versions of CXF and Axis2 are available containing some critical security fixes that need to be made available for Geronimo 2.1.x and 2.2.x. Details of the exposure can be found here:

        https://svn.apache.org/repos/asf/axis/axis2/java/core/security/CVE-2010-1632.pdf
        https://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf
        Rick McGuire created issue -

          People

          • Assignee:
            Rick McGuire
            Reporter:
            Rick McGuire
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development