CVE-2024-28752: Apache Cxf

Critical severity, CVSS 9.3. EPSS: 2.5% chance of exploitation in the next 30 days.

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

Affected products

  • Apache Cxf: before 3.5.8 (fixed in 3.5.8); from 3.6.0, before 3.6.3 (fixed in 3.6.3); from 4.0.0, before 4.0.4 (fixed in 4.0.4)
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Ontap Tools: version 10 only

Published 2024-03-15. Last modified 2026-06-17.