Описание
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
A server-side request forgery (SSRF) vulnerability was found in Apache CXF. This issue occurs in attacks on webservices that take at least one parameter of any type, and when Aegisdatabind is used. Users of other data bindings including the default databinding are not impacted.
Отчет
Red Hat rates this as an Important impact due to the fact this requires Aegis databind, which is not the default databinding for Apache CXF.
Меры по смягчению последствий
No mitigation is currently available for this vulnerability. Please make sure to update as the fixes become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | com.amazon.opendistroforelasticsearch-opendistro_security | Not affected | ||
| Red Hat Build of Keycloak | cxf-core | Not affected | ||
| Red Hat Data Grid 8 | cxf-core | Not affected | ||
| Red Hat Fuse 7 | cxf-core | Affected | ||
| Red Hat JBoss Data Grid 7 | cxf-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cxf-core | Not affected | ||
| Red Hat Process Automation 7 | cxf-core | Not affected | ||
| Red Hat Single Sign-On 7 | cxf-core | Fix deferred | ||
| streams for Apache Kafka | cxf-core | Not affected | ||
| Important: Red Hat JBoss Enterprise Application Platform 7.4.17 Security update | cxf-core | Fixed | RHSA-2024:3563 | 03.06.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
SSRF vulnerability using the Aegis DataBinding in Apache CXF
Уязвимость каркаса для веб-сервисов Apache CXF, существующая из-за недостаточной проверки вводимых пользователем данных, позволяющая нарушителю осуществить SSRF-атаку
EPSS
7.4 High
CVSS3