CVE-2024-28752

CRITICAL NUCLEI

Apache CXF < 3.5.8 - Server-Side Request Forgery via Aegis DataBinding

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-28752. PoCs published by ReaJason. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2024-28752, an SSRF vulnerability in Apache CXF. The exploit demonstrates how an attacker can use the `xop:Include` tag in a SOAP request to read arbitrary files from the server.

Description

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Exploits (1)

nomisec WORKING POC 1 stars
by ReaJason · poc
https://github.com/ReaJason/CVE-2024-28752

This repository contains a proof-of-concept exploit for CVE-2024-28752, an SSRF vulnerability in Apache CXF. The exploit demonstrates how an attacker can use the `xop:Include` tag in a SOAP request to read arbitrary files from the server.

Classification
Working Poc 95%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: Apache CXF
No auth needed
Prerequisites: Apache CXF service exposed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Apache CXF < 4.0.4 - Aegis DataBinding SSRF / Local File Read
HIGHVERIFIEDby maciejklimek
Shodan: http.component:"Apache CXF"
FOFA: body="Apache CXF"

Scores

CVSS v3 9.3
EPSS 0.4660
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (4)
apache/cxf < 3.5.8
netapp/oncommand_workflow_automation
netapp/ontap_tools 10
org.apache.cxf/cxf-rt-databinding-aegis 0 - 3.5.8Maven
Published Mar 15, 2024
Tracked Since Feb 18, 2026