Description
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Remediation
References
https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944472739&api=v2
Related Vulnerabilities
CVE-2022-34178 Vulnerability in maven package org.jenkins-ci.plugins:embeddable-build-status
CVE-2019-10411 Vulnerability in maven package com.inedo.buildmaster:inedo-buildmaster
CVE-2022-23708 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2014-7810 Vulnerability in maven package org.mortbay.jasper:apache-el
CVE-2011-2732 Vulnerability in maven package org.springframework.security:spring-security-core