CVE-2024-32007

CVE-2024-32007: Apache CXF Denial of Service vulnerability in JOSE

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-400
Published July 19, 2024
Last update September 13, 2024

CVSS base score

What the vulnerability does

Description

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

Key dates

Disclosure timeline

July 19, 2024 CVE published
September 13, 2024 Record updated