SSRF Vulnerability in Apache CXF 

Issue date: 06-11-2024
Affects versions: 16.0, 15.6, 14.7

Security Issue ID

SECURITY-576

 

Affected Product Version(s)

14.7.21, 15.6.0, 16.0.0  (and previous patch releases)

 

Severity 

Critical

 

Description

CVE-2024-29736

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

CVSS v3 Base Score: 9.8

CWE-918: Server-Side Request Forgery (SSRF)

Instructions

Customers are recommended to upgrade to the latest version. As of the time of writing,  14.7.22, 15.7.0, 16.1.0.