SSRF Vulnerability in Apache CXF Could Allow Attacker to Perform SSRF Style Attacks
CVE-2024-28752

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
15 March 2024

Summary

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Affected Version(s)

Apache CXF 0 < 4.0.4, 3.6.3, 3.5.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tobias S. Fink
.