Bug 2270732 (CVE-2024-28752)

Summary: CVE-2024-28752 cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aileenc, asoldano, bbaranow, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, chfoley, cmiranda, darran.lofthouse, dhanak, dkreling, dosoudil, dpalmer, drichtar, ecerquei, fjuma, fmariani, fmongiar, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jcantril, jkoops, jnethert, jpoth, jrokos, jscholz, kverlaen, lgao, mnovotny, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pcongius, pdelbell, pdrozd, peholase, pesilva, pjindal, pmackay, pskopek, rguimara, rmartinc, rojacob, rowaters, rstancel, rstepani, smaestri, sthorger, swoodman, tcunning, tom.jenkinson, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: cxf-core 3.5.8, cxf-core 3.6.3, cxf-core 4.0.4 Doc Type: If docs needed, set a value
Doc Text:
A server-side request forgery (SSRF) vulnerability was found in Apache CXF. This issue occurs in attacks on webservices that take at least one parameter of any type, and when Aegisdatabind is used. Users of other data bindings including the default databinding are not impacted.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2270719    

Description Patrick Del Bello 2024-03-21 15:15:01 UTC
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt

Comment 7 errata-xmlrpc 2024-06-03 16:58:48 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7

Via RHSA-2024:3559 https://access.redhat.com/errata/RHSA-2024:3559

Comment 8 errata-xmlrpc 2024-06-03 16:59:44 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Via RHSA-2024:3561 https://access.redhat.com/errata/RHSA-2024:3561

Comment 9 errata-xmlrpc 2024-06-03 17:00:10 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8

Via RHSA-2024:3560 https://access.redhat.com/errata/RHSA-2024:3560

Comment 10 errata-xmlrpc 2024-06-03 17:10:34 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2024:3563 https://access.redhat.com/errata/RHSA-2024:3563

Comment 11 errata-xmlrpc 2024-06-06 16:42:18 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 3.20.6 for Spring Boot

Via RHSA-2024:3708 https://access.redhat.com/errata/RHSA-2024:3708

Comment 12 errata-xmlrpc 2024-08-15 20:07:06 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2024:5482 https://access.redhat.com/errata/RHSA-2024:5482

Comment 13 errata-xmlrpc 2024-08-15 20:08:31 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8

Via RHSA-2024:5479 https://access.redhat.com/errata/RHSA-2024:5479

Comment 14 errata-xmlrpc 2024-08-15 20:09:12 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9

Via RHSA-2024:5481 https://access.redhat.com/errata/RHSA-2024:5481

Comment 15 errata-xmlrpc 2024-10-22 18:29:42 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.8

Via RHSA-2024:8339 https://access.redhat.com/errata/RHSA-2024:8339

Comment 16 errata-xmlrpc 2024-11-25 00:10:45 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7

Via RHSA-2024:10208 https://access.redhat.com/errata/RHSA-2024:10208

Comment 17 errata-xmlrpc 2024-11-25 00:11:33 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7

Via RHSA-2024:10207 https://access.redhat.com/errata/RHSA-2024:10207