Skip to content

SSRF vulnerability using the Aegis DataBinding in Apache CXF

Moderate severity GitHub Reviewed Published Mar 15, 2024 to the GitHub Advisory Database • Updated May 2, 2024

Package

maven org.apache.cxf:cxf-core (Maven)

Affected versions

< 3.5.8
>= 3.6.0, < 3.6.3
>= 4.0.0, < 4.0.4

Patched versions

3.5.8
3.6.3
4.0.4

Description

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

References

Published by the National Vulnerability Database Mar 15, 2024
Published to the GitHub Advisory Database Mar 15, 2024
Reviewed Mar 15, 2024
Last updated May 2, 2024

Severity

Moderate

Weaknesses

CVE ID

CVE-2024-28752

GHSA ID

GHSA-qmgx-j96g-4428

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.