Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-42404

5 месяцев назад

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-42404

5 месяцев назад

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-287c-fxr7-3w6c

5 месяцев назад

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-11867

5 месяцев назад

Уязвимость программного интерфейса класса PolicyReference Java-фреймворка Apache Neethi, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-42404

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-42404

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-287c-fxr7-3w6c

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

CVSS3: 6.5
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-11867

Уязвимость программного интерфейса класса PolicyReference Java-фреймворка Apache Neethi, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.2
0%
Низкий
5 месяцев назад

Уязвимостей на страницу