[MAVEN:GHSA-X3X3-QWJQ-8GJ4] Apache CXF Server-Side Request Forgery vulnerability

Severity Critical
Affected Packages 2
Fixed Packages 2
CVEs 1

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

Package Affected Version
pkg:maven/org.apache.cxf/cxf-core >= 3.5.0, < 3.5.5
pkg:maven/org.apache.cxf/cxf-core < 3.4.10
ID
MAVEN:GHSA-X3X3-QWJQ-8GJ4
Severity
critical
URL
https://github.com/advisories/GHSA-x3x3-qwjq-8gj4
Published
2022-12-13T18:30:26
(21 months ago)
Modified
2023-01-31T05:06:51
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core >= 3.5.0 < 3.5.5
Fixed pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core = 3.5.5
Affected pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core < 3.4.10
Fixed pkg:maven/org.apache.cxf/cxf-core org.apache.cxf cxf-core = 3.4.10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...