Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42404

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

A flaw was found in Apache Neethi. When an application explicitly calls the PolicyReference API to retrieve a policy from a remote Uniform Resource Identifier (URI), Apache Neethi does not impose restrictions on the URI. This allows a remote attacker to cause the application to make outbound requests to arbitrary protocols and internal IP addresses. This could lead to information disclosure or enable further network-based attacks.

Меры по смягчению последствий

To mitigate this issue, restrict outbound network access for applications that utilize Apache Neethi's PolicyReference API, especially if they process untrusted input that could influence the URI used for fetching remote policies. Implement firewall rules or network policies to limit the protocols and IP addresses to which the application can connect. This may impact application functionality if legitimate remote policy fetching is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3neethiAffected
Red Hat build of Apache Camel for Spring Boot 4neethiFix deferred
Red Hat Fuse 7neethiFix deferred
Red Hat JBoss Enterprise Application Platform 7neethiFix deferred
Red Hat JBoss Enterprise Application Platform 8neethiFix deferred
Red Hat JBoss Enterprise Application Platform Expansion PackneethiFix deferred
Red Hat Process Automation 7neethiFix deferred
Red Hat Single Sign-On 7neethiFix deferred
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27neethiFixedRHSA-2026:1983520.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2464324Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 6.5
github
3 месяца назад

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

5.3 Medium

CVSS3