Lucene search

K
osvGoogleOSV:CVE-2024-34580
HistoryJun 26, 2024 - 5:15 a.m.

CVE-2024-34580

2024-06-2605:15:00
Google
osv.dev
10
apache xml security
xml signature syntax
ssrf payload

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

7.2

Confidence

Low

EPSS

0.936

Percentile

99.2%

Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the supplier disputes this CVE Record on the grounds that they are implementing the specification β€œcorrectly” and are not β€œat fault.”

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

7.2

Confidence

Low

EPSS

0.936

Percentile

99.2%