Description
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Remediation
References
https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944472739&api=v2
Related Vulnerabilities
CVE-2012-0818 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-dao
CVE-2020-2139 Vulnerability in maven package org.jenkins-ci.plugins:cobertura
CVE-2019-8331 Vulnerability in maven package org.fujion.webjars:bootstrap
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server