CVE-2022-46364
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
- Affected products
- Apache Cxf
- Apache Cxf
- < 3.4.10, 3.5.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2022-12-13
CVE-2022-46364 at NVD
12 known exploits for CVE-2022-46364
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2022-46364-Poc
CVE-2022-46364-Proof-of-the-concept
CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC
CVE-2022-46364-poc
CVE-2022-46364
CVE-2022-46364-htb-ctf
Exploit for Server-Side Request Forgery in Apache Cxf
ffensive-playbook
ofensive-playbook
Exploit for Server-Side Request Forgery in Apache Cxf
Exploit for Server-Side Request Forgery in Apache Cxf
Exploit for Server-Side Request Forgery in Apache Cxf