Medium severity6.3NVD Advisory· Published Aug 20, 2025· Updated Jun 17, 2026
CVE-2024-39954
CVE-2024-39954
Description
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read or update internal resources. Users are recommended to upgrade to version 1.12.0 or use the master branch , which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.eventmesh:eventmesh-runtimeMaven | >= 1.6.0-release, <= 1.11.0-release | — |
Affected products
3- Apache Software Foundation/Apache EventMesh Runtimev5Range: 1.6.0
- ghsa-coordsRange: >= 1.6.0-release, <= 1.11.0-release
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-hf86-8x8v-h7vcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39954ghsaADVISORY
- lists.apache.org/thread/v6c96zygqx8xc2k3n2d59mgnm5txhkonnvdMailing ListWEB
News mentions
0No linked articles in our index yet.