← Back

CVE-2024-28752

Published: Mar 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.8
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Affected (5)

1 product
Cxf
2 products
Oncommand Workflow Automation
Ontap Tools
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 3.5.8
From 3.6.0 to 3.6.3
From 4.0.0 to 4.0.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Version 10

References (6)

Source: security@apache.org
Mailing List
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.