Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9gj-rqrw-x4fq

Опубликовано: 14 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Server Side Request Forgery in Apache Axis

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Пакеты

Наименование

org.apache.axis:axis

maven
Затронутые версииВерсия исправления

<= 1.4

Отсутствует

Наименование

axis:axis

maven
Затронутые версииВерсия исправления

<= 1.4

Отсутствует

EPSS

Процентиль: 100%
0.90738
Критический

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS3: 8
redhat
почти 7 лет назад

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS3: 7.5
nvd
почти 7 лет назад

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS3: 7.5
debian
почти 7 лет назад

A Server Side Request Forgery (SSRF) vulnerability affected the Apache ...

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость платформы веб-сервисов Apache Axis, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 100%
0.90738
Критический

7.5 High

CVSS3

Дефекты

CWE-918