CVE-2024-28752
CRITICAL NUCLEIApache Cxf < 3.5.8 - SSRF
Title source: ruleDescription
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
Exploits (1)
Nuclei Templates (1)
Apache CXF < 4.0.4 - Aegis DataBinding SSRF / Local File Read
HIGHVERIFIEDby maciejklimek
Shodan:
http.component:"Apache CXF"
FOFA:
body="Apache CXF"
Scores
CVSS v3
9.3
EPSS
0.4650
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Details
CWE
CWE-918
Status
published
Products (4)
apache/cxf
< 3.5.8
netapp/oncommand_workflow_automation
netapp/ontap_tools
10
org.apache.cxf/cxf-rt-databinding-aegis
0 - 3.5.8Maven
Published
Mar 15, 2024
Tracked Since
Feb 18, 2026