A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
The vulnerability is present only in configurations using Aegis DataBinding — the default databinding mechanism is not vulnerable. An attacker can prepare appropriately malicious input data and pass it to any web service built on Apache CXF with Aegis DataBinding, provided it accepts at least one parameter of any type. The server processes this data and may be induced to execute HTTP requests to internal or external resources that the attacker would not normally have access to.
An attacker can gain unauthorized access to internal network resources (SSRF), read sensitive information, and affect the integrity of operations performed by the server on behalf of the attacker. This can lead to exposure of internal infrastructure and escalation to further attacks on the internal network.
Apache CXF should be updated to version 4.0.4, 3.6.3, or 3.5.8 (depending on the branch used). If an update is not immediately possible, consider switching to the default databinding mechanism instead of Aegis DataBinding. NetApp product users should apply patches according to the manufacturer's recommendations available at security.netapp.com.
Apache CXF in versions before 4.0.4, before 3.6.3, and before 3.5.8, only when Aegis DataBinding is used. It also affects NetApp products: OnCommand Workflow Automation and ONTAP Tools (versions specified in NetApp manufacturer references).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NApache Cxf
APPApache< 3.5.83.6.0 – 3.6.3 (excl.)4.0.0 – 4.0.4 (excl.)Netapp Oncommand Workflow Automation
APPNetappall versionsNetapp Ontap Tools
APPNetapp10
Related vulnerabilities
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
Apache CXF: brak walidacji scope w rejestracji klienta OAuth2
Apache CXF: podmiana parametrów PKCE i OIDC przez JWT w JwtRequestCodeFilter
Apache CXF: pominięcie walidacji tokenów OIDC umożliwia authentication bypass