You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@geronimo.apache.org by "Shawn Jiang (JIRA)" <ji...@apache.org> on 2010/09/22 16:44:32 UTC

[jira] Closed: (GERONIMO-5383) CVE-2010-1632 and CVE-2010-2076: Axis2 and CXF HTTP binding enables DTD based XML attacks.

     [ https://issues.apache.org/jira/browse/GERONIMO-5383?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Shawn Jiang closed GERONIMO-5383.
---------------------------------

    Resolution: Fixed

The fix is included in Axis2 1.5.2 and CXF 2.1.10.    CXF 2.1.10 has been in 2.2 branch.   Axis2 1.5.2 was just released and included in 2.2 branch too. 

Closing this.

> CVE-2010-1632 and CVE-2010-2076: Axis2 and CXF HTTP binding enables DTD based XML attacks. 
> -------------------------------------------------------------------------------------------
>
>                 Key: GERONIMO-5383
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-5383
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: webservices
>    Affects Versions: 2.1.5, 2.2
>            Reporter: Rick McGuire
>            Assignee: Rick McGuire
>            Priority: Critical
>             Fix For: 2.2.1, 2.1.6
>
>
> New versions of CXF and Axis2 are available containing some critical security fixes that need to be made available for Geronimo 2.1.x and 2.2.x.  Details of the exposure can be found here: 
> https://svn.apache.org/repos/asf/axis/axis2/java/core/security/CVE-2010-1632.pdf
> https://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.