← Back

CVE-2022-46364

nvd nist
Published: Dec 13, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

Affected (2)

Products: Apache: Cxf
1 product
Cxf
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 3.4.10
From 3.5.0 to 3.5.5

Timeline

No history available yet.