Back to search
CVE-2024-29736
Published: Jul 19, 2024
Modified: Nov 15, 2024
PUBLISHED
Description
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache CXF | affected 0 - < 3.5.9, 3.6.4, 4.0.5 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now