CERT-In Vulnerability Note
CIVN-2023-0028
Server-Side Request Forgery Vulnerability in Red Hat JBossEnterprise Application
Original Issue Date:January 20, 2023
Severity Rating: MEDIUM
Software Affected
- JBoss Enterprise Application Platform Text-Only Advisories x86_64
- JBoss Enterprise Application Platform 7.4 for RHEL 9 x86_64
- JBoss Enterprise Application Platform 7.4 for RHEL 8 x86_64
- JBoss Enterprise Application Platform 7.4 for RHEL 7 x86_64
- Apache CXF versions before 3.5.5 and 3.4.10
Overview
A vulnerability has been reported in Red Hat JBossEnterprise Application which could allow a remote attacker to gain access to sensitive data located in the local network or send malicious requests to other servers from the targeted system.
Description
This vulnerability exists due to insufficient validation of user-supplied input when parsing the href attribute of XOP: Include in MTOM requests in versions of Apache CXF. A remote attacker could exploit the vulnerability by sending specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote to gain access to sensitive data located in the local network or send malicious requests to other servers from the targeted system.
Solution
Apply appropriate patches as mentioned in the following link
https://access.redhat.com/errata/RHSA-2023:0163
https://access.redhat.com/errata/RHSA-2023:0164
Vendor Information
RedHat
https://access.redhat.com/errata/RHSA-2023:0163
https://access.redhat.com/errata/RHSA-2023:0164
References
RedHat
https://access.redhat.com/errata/RHSA-2023:0163
https://access.redhat.com/errata/RHSA-2023:0164
CVE Name
CVE-2022-46364
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|