Vulnerability GHSA-x3x3-qwjq-8gj4

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
3 years ago
December 13, 2022 at 06:30 PM UTC
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5

Summary

Apache CXF Server-Side Request Forgery vulnerability

Details

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

Impacted packages

Timeline

Published
3 years ago
December 13, 2022 at 06:30 PM UTC
Fixed (3.4.10)
Unknown
Unknown
Fixed (3.5.5)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 04:10 AM UTC