← back
CVE-2024-29736highCWE-918

Apache CXF: SSRF vulnerability via WADL stylesheet parameter

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N