CVE-2024-32007

Denial of Service
Affects
Apache CXF (org.apache.cxf:cxf-rt-rs-security-jose)
in
Apache CXF
No items found.
Versions
<3.5.9, >=3.6.0 <3.6.4, >=4.0.0 <4.0.5

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

A Denial of Service (DoS) vulnerability (CVE-2024-32007) has been identified in the Apache CXF JOSE module (org.apache.cxf:cxf-rt-rs-security-jose), which allows attackers to exhaust server CPU by sending a password-based (PBES2) encrypted JWE token whose p2c header carries a very large PBKDF2 iteration count.

Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others.

This issue affects versions before 3.5.9, versions 3.6.0 through 3.6.3, and versions 4.0.0 through 4.0.4 of Apache CXF, including the End-of-Life 3.4.x line.

Details

Module Info

Vulnerability Info

JWE tokens that use the PBES2 key management algorithms (PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW) derive the key-wrapping key from a shared password with PBKDF2. The salt (p2s) and the iteration count (p2c) are both taken from the JWE protected header, which is controlled by whoever produced the token. When a CXF JAX-RS endpoint is configured to decrypt JWE with a password, JweUtils builds a PbesHmacAesWrapKeyDecryptionAlgorithm from the configured password:

char[] password = provider != null ? provider.getPassword(props) : null;
if (password == null) {
    throw new JweException(JweException.Error.KEY_DECRYPTION_FAILURE);
}
keyDecryptionProvider = new PbesHmacAesWrapKeyDecryptionAlgorithm(new String(password));

The decryption algorithm then reads p2c straight from the untrusted header and passes it to the PBKDF2 derivation without any upper bound:

@Override
public byte[] getDecryptedContentEncryptionKey(JweDecryptionInput jweDecryptionInput) {
    JweHeaders jweHeaders = jweDecryptionInput.getJweHeaders();
    byte[] saltInput = getDecodedBytes(jweHeaders.getHeader("p2s"));
    int pbesCount = jweHeaders.getIntegerHeader("p2c");
    String keyAlgoJwt = jweHeaders.getKeyEncryptionAlgorithm().getJwaName();
    int keySize = PbesHmacAesWrapKeyEncryptionAlgorithm.getKeySize(keyAlgoJwt);
    byte[] derivedKey = PbesHmacAesWrapKeyEncryptionAlgorithm
        .createDerivedKey(keyAlgoJwt, keySize, password, saltInput, pbesCount);
    // ...
}

The key derivation runs before the wrapped key or the ciphertext is authenticated, so the attacker does not need to know the password. A single token with p2c set to a value near Integer.MAX_VALUE forces billions of HMAC rounds on a request-handling thread, and a handful of such requests is enough to tie up the server's CPU and make the service unavailable to legitimate clients.

Mitigation

Only recent versions of Apache CXF receive community support. Older lines are End-of-Life and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Jingcheng Yang from Sichuan University and Zhongguancun Lab (finder)
  • Jianjun Chen from Sichuan University and Zhongguancun Lab (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2024-32007
PROJECT Affected
Apache CXF (org.apache.cxf:cxf-rt-rs-security-jose)
Versions Affected
<3.5.9, >=3.6.0 <3.6.4, >=4.0.0 <4.0.5
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
September 30, 2026
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.