VDB

ANCHORE-2024-29736

ANCHORE-2024-29736 PUBLISHED

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

Affected Products

VendorProductVersions
Apache Software FoundationApache CXF3.6, 4, 0

Timeline

  • Jul 19, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›