Description
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
References (4)
Scores
CVSS v3
9.8
EPSS
0.0076
EPSS Percentile
73.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-190
CWE-680
Status
published
Products (3)
fedoraproject/fedora
33
fedoraproject/fedora
34
genivia/gsoap
2.8.107
Published
Feb 10, 2021
Tracked Since
Feb 18, 2026