VYPR

Maven package

org.apache.cxf/cxf-rt-management

pkg:maven/org.apache.cxf/cxf-rt-management

Vulnerabilities (1)

  • CVE-2020-1954Apr 1, 2020
    affected < 3.2.13fixed 3.2.13

    Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) st