SSRF Vulnerability in Apache CXF
Issue date: 06-11-2024Affects versions: 16.0, 15.6, 14.7
Security Issue ID
SECURITY-576
Affected Product Version(s)
14.7.21, 15.6.0, 16.0.0 (and previous patch releases)
Severity
Critical
Description
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
CVSS v3 Base Score: 9.8
CWE-918: Server-Side Request Forgery (SSRF)
Instructions
Customers are recommended to upgrade to the latest version. As of the time of writing, 14.7.22, 15.7.0, 16.1.0.