Back

CRITICAL

Apache CXF SSRF Vulnerability using the Aegis databinding

Published Mar 15, 2024

Description

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Affected products

Remediation

Red Hat statement

Red Hat rates this as an Important impact due to the fact this requires Aegis databind, which is not the default databinding for Apache CXF.

Red Hat mitigation

No mitigation is currently available for this vulnerability. Please make sure to update as the fixes become available.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 15, 2024
Updated Feb 13, 2025
Reserved Mar 8, 2024
CISA Vulnrichment
Updated Jul 20, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 14, 2024
GHSA-QMGX-J96G-4428