VYPR

Maven package

org.apache.cxf/cxf-rt-rs-service-description

pkg:maven/org.apache.cxf/cxf-rt-rs-service-description

Vulnerabilities (1)

  • CVE-2024-29736Jul 19, 2024
    affected >= 4.0.0, < 4.0.5fixed 4.0.5

    A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.