CVE-2024-28752

Scores

EPSS

0.571medium57.1%
0%20%40%60%80%100%

Percentile: 57.1%

CVSS

7.4high3.x
0246810

CVSS Score: 7.4/10

All CVSS Scores

CVSS 3.x
7.4

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

anchore_overridesnvdredhat

CWEs

CWE-918

Related Vulnerabilities

Exploits

Exploit ID: CVE-2024-28752

Source: github-poc

URL: https://github.com/ReaJason/CVE-2024-28752

Vulnerable Software (62)

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:org.apache.cxf:cxf-rt-databinding-aegis:*:*:*:*:*:maven:*:*",          "versionEndExcluding": "3.5.8"        }...

Source: anchore_overrides

Type: Configuration

Product: eap7-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "3.1.16-3.SP1_redhat_00001.1.ep7.el7"}

Source: redhat

Type: Configuration

Product: eap7-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "3.4.10-1.SP1_redhat_00001.1.el7eap"}

Source: redhat

Type: Configuration

Product: eap7-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "3.5.8-1.redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap7-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "3.5.8-1.redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap7-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "3.5.8-1.redhat_00001.1.el7eap"}

Source: redhat

Type: Configuration

Product: eap7-avro

Operating System: rhel

Trait:
{  "fixed": "1.7.6-2.redhat_00003.1.ep7.el7"}

Source: redhat

Type: Configuration

Product: eap7-avro

Operating System: rhel

Trait:
{  "fixed": "1.7.6-8.redhat_00003.1.el7eap"}

Source: redhat

Type: Configuration

Product: eap7-bouncycastle

Operating System: rhel

Trait:
{  "fixed": "1.68.0-1.redhat_00005.1.ep7.el7"}

Source: redhat

Type: Configuration

Product: eap7-h2database

Operating System: rhel

Trait:
{  "fixed": "1.4.197-2.redhat_00005.1.ep7.el7"}

Source: redhat

Type: Configuration

Product: eap7-h2database

Operating System: rhel

Trait:
{  "fixed": "1.4.197-3.redhat_00004.1.el7eap"}

Source: redhat

Type: Configuration

Product: eap7-hal-console

Operating System: rhel

Trait:
{  "fixed": "3.3.22-1.Final_redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap7-hal-console

Operating System: rhel

Trait:
{  "fixed": "3.3.22-1.Final_redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap7-infinispan

Operating System: rhel

Trait:
{  "fixed": "11.0.19-2.Final_redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap7-infinispan

Operating System: rhel

Trait:
{  "fixed": "11.0.19-2.Final_redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap7-jackson-databind

Operating System: rhel

Trait:
{  "fixed": "2.8.11.6-1.SP1_redhat_00001.1.ep7.el7"}

Source: redhat

Type: Configuration

Product: eap7-jboss-annotations-api_1.3_spec

Operating System: rhel

Trait:
{  "fixed": "2.0.1-4.Final_redhat_00001.1.el7eap"}

Source: redhat

Type: Configuration

Product: eap7-jboss-ejb-client

Operating System: rhel

Trait:
{  "fixed": "4.0.54-3.Final_redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap7-jboss-ejb-client

Operating System: rhel

Trait:
{  "fixed": "4.0.54-3.Final_redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap7-jboss-jsf-api_2.3_spec

Operating System: rhel

Trait:
{  "fixed": "3.0.0-8.SP08_redhat_00001.1.el9eap"}

Source: redhat