Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-46364

Опубликовано: 13 дек. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

A SSRF vulnerability was found in Apache CXF. This issue occurs when parsing the href attribute of XOP:Include in MTOM requests, allowing an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

Отчет

Red Hat Integration Camel Quarkus does not support CXF extensions and so is affected at a reduced impact of Moderate. The RHSSO server does not ship Apache CXF. The component mentioned in CVE-2022-46364 is a transitive dependency coming from Fuse adapters and the test suite.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat build of QuarkusCXFAffected
Red Hat Data Grid 8CXFAffected
Red Hat Integration Camel K 1CXFNot affected
Red Hat Integration Camel Quarkus 1CXFNot affected
Red Hat JBoss Data Grid 7CXFOut of support scope
Red Hat JBoss Data Virtualization 6CXFOut of support scope
Red Hat JBoss Enterprise Application Platform 6apache-cxfOut of support scope
Red Hat JBoss Enterprise Application Platform 6apache-cxf-xjc-utilsOut of support scope
Red Hat JBoss Enterprise Application Platform 6CXFOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918

EPSS

Процентиль: 34%
0.00135
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

CVSS3: 9.8
github
около 3 лет назад

Apache CXF Server-Side Request Forgery vulnerability

EPSS

Процентиль: 34%
0.00135
Низкий

9.8 Critical

CVSS3