Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: apache/cxf

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
4.1.x
4.0.x
<= 3.6.x

Reporting a Vulnerability

For information on how to report a new security problem please see here. Our existing security advisories are published here.

Threat Model

What CXF treats as in scope and out of scope, the security properties it provides and the ones it disclaims, the adversary model, and how inbound reports and tool/AI findings are triaged are documented in THREAT_MODEL.md. Because CXF is a framework, many of those properties are conditional on how the integrator configures it; the integrator-responsibilities and known-non-findings sections of that document are the most useful starting points for triaging a report.

There aren't any published security advisories

Morty Proxy This is a proxified and sanitized view of the page, visit original site.