cbcvebase.
CVE-2024-29736
published 2024-07-19

CVE-2024-29736: A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on…

PriorityP355critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.03%
59.9th percentile
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.5.93.5.9
apachecxf>= 3.6.0 < 3.6.43.6.4
apachecxf>= 4.0.0 < 4.0.54.0.5
apache_software_foundationapache_cxf< 3.5.9, 3.6.4, 4.0.53.5.9, 3.6.4, 4.0.5

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.