← Back

CVE-2024-29736

nvd nist
Published: Jul 19, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

Affected (3)

Products: Apache: Cxf
1 product
Cxf
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 3.5.9
From 3.6.0 to 3.6.4
From 4.0.0 to 4.0.5

References (4)

Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.