Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29736

Опубликовано: 19 июл. 2024
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

A Server-side request forgery (SSRF) vulnerability was found in Apache CXF in the WADL service description. The flaw allows an attacker to perform SSRF-style attacks on REST web services. The attack only applies if a custom stylesheet parameter is configured.

Отчет

This SSRF vulnerability in Apache CXF's WADL service description is of significant severity because it allows an attacker to manipulate server-side requests, potentially leading to unauthorized access to internal resources. By exploiting this flaw, an attacker can craft malicious requests that bypass traditional security controls, enabling the server to communicate with internal systems, which may include databases, cloud services, or other sensitive infrastructure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7org.apache.cxf/cxf-rt-rs-service-descriptionAffected
Red Hat Integration Camel K 1org.apache.cxf/cxf-rt-rs-service-descriptionWill not fix
Red Hat JBoss Data Grid 7org.apache.cxf/cxf-rt-rs-service-descriptionWill not fix
Red Hat JBoss Enterprise Application Platform 7cxf-rt-rs-service-descriptionAffected
Red Hat JBoss Enterprise Application Platform 8cxf-rt-rs-service-descriptionNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-rs-service-descriptionNot affected
Red Hat build of Apache Camel 3.20.7 for Spring BootFixedRHSA-2024:688319.09.2024
Red Hat build of Apache Camel 4.4.0 for Spring BootFixedRHSA-2024:270706.05.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2298827apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter

EPSS

Процентиль: 57%
0.00351
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

CVSS3: 5.9
github
больше 1 года назад

Apache CXF: SSRF vulnerability via WADL stylesheet parameter

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость технологии WADL (Web Application Description Language) каркаса для веб-сервисов Apache CXF, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 57%
0.00351
Низкий

9.1 Critical

CVSS3