Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28752

Опубликовано: 14 мар. 2024
Источник: redhat
CVSS3: 7.4

Описание

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

A server-side request forgery (SSRF) vulnerability was found in Apache CXF. This issue occurs in attacks on webservices that take at least one parameter of any type, and when Aegisdatabind is used. Users of other data bindings including the default databinding are not impacted.

Отчет

Red Hat rates this as an Important impact due to the fact this requires Aegis databind, which is not the default databinding for Apache CXF.

Меры по смягчению последствий

No mitigation is currently available for this vulnerability. Please make sure to update as the fixes become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftcom.amazon.opendistroforelasticsearch-opendistro_securityNot affected
Red Hat Build of Keycloakcxf-coreNot affected
Red Hat Data Grid 8cxf-coreNot affected
Red Hat JBoss Data Grid 7cxf-coreOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-coreNot affected
Red Hat Process Automation 7cxf-coreNot affected
Red Hat Single Sign-On 7cxf-coreFix deferred
streams for Apache Kafkacxf-coreNot affected
Red Hat build of Apache Camel 3.20.6 for Spring BootFixedRHSA-2024:370806.06.2024
Red Hat build of Apache Camel 4 for Quarkus 3FixedRHSA-2024:283416.05.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2270732cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.3
nvd
больше 2 лет назад

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

CVSS3: 9.3
github
больше 2 лет назад

SSRF vulnerability using the Aegis DataBinding in Apache CXF

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, существующая из-за недостаточной проверки вводимых пользователем данных, позволяющая нарушителю осуществить SSRF-атаку

7.4 High

CVSS3