Vulnerability GHSA-x3x3-qwjq-8gj4
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
3 years ago
December 13, 2022 at 06:30 PM UTC
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
Summary
Apache CXF Server-Side Request Forgery vulnerability
Details
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
Critical
3 months ago
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
Medium Risk
1 year ago
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
4.1.0 GHSA-36wv-v2qp-v4g4
4.1.0 GHSA-36wv-v2qp-v4g4
High Risk
1 year ago
Apache CXF: Denial of Service vulnerability with temporary files
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
High Risk
3 years ago
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
Impacted packages
Timeline
Published
3 years ago
December 13, 2022 at 06:30 PM UTC
Fixed (3.4.10)
Unknown
Unknown
Fixed (3.5.5)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 04:10 AM UTC