CVE-2022-46364
CRITICAL9.8EPSS 0.10%Apache CXF Server-Side Request Forgery vulnerability
發布日:2022/12/13修改日:2023/11/8
描述
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
受影響套件(1)
- Maven/org.apache.cxf:cxf-corefrom 0, < 3.4.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |