A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
                
            References
                    Configurations
                    History
                    21 Nov 2024, 07:30
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944472739&api=v2 - Vendor Advisory | 
07 Nov 2023, 03:55
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. | 
Information
                Published : 2022-12-13 17:15
Updated : 2025-04-22 03:15
NVD link : CVE-2022-46364
Mitre link : CVE-2022-46364
CVE.ORG link : CVE-2022-46364
JSON object : View
Products Affected
                apache
- cxf
CWE
                
                    
                        
                        CWE-918
                        
            Server-Side Request Forgery (SSRF)
