CVE-2024-28752
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
A Server-Side Request Forgery (SSRF) vulnerability (CVE-2024-28752) has been identified in the Aegis databinding of Apache CXF, which allows attackers to make the server fetch arbitrary URLs of their choosing by sending a SOAP request whose xop:Include href does not match any attachment in the message. The attack works against any web service that uses the Aegis databinding and takes at least one parameter of any type. Services using other databindings, including the default databinding, are not affected.
Per OWASP: In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. The attacker can supply or modify a URL which the code running on the server will read or submit data to, and by carefully selecting the URLs, the attacker may be able to read server configuration such as AWS metadata, connect to internal services like http enabled databases or perform post requests towards internal services which are not intended to be exposed.
This issue affects versions before 3.5.8, 3.6.0 through 3.6.2, and 4.0.0 through 4.0.3 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-databinding-aegis - Affected versions: <3.5.8, >=3.6.0 <3.6.3, >=4.0.0 <4.0.4
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-databinding-aegis
- Package manager: Maven
- Fixed in:
- OSS Apache CXF 3.5.8, 3.6.3, 4.0.4
- NES for Apache CXF v3.4.12
Vulnerability Info
This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-databinding-aegis package in versions before 3.5.8, 3.6.0 through 3.6.2, and 4.0.0 through 4.0.3 of Apache CXF.
The Aegis databinding supports MTOM/XOP, where binary content in a SOAP body is replaced by an xop:Include element whose href attribute points at a MIME attachment. When Aegis reads such an element, AbstractXOPType.readInclude takes the href value straight from the incoming XML and passes it to AttachmentUtil.getAttachment:
private Object readInclude(String type, MessageReader reader,
Context context) throws DatabindingException {
String href = reader.getAttributeReader(XOP_HREF).getValue().trim();
Attachment att = AttachmentUtil.getAttachment(href, context.getAttachments());
// ...
}AttachmentUtil.getAttachment first looks for a message attachment whose Content-ID matches the href. If none matches, it does not reject the reference. Instead it treats the attacker-supplied value as a URL and opens it with a URLDataSource:
public static Attachment getAttachment(String id, Collection<Attachment> attachments) {
if (id == null) {
throw new DatabindingException("Cannot get attachment: null id");
}
int i = id.indexOf("cid:");
if (i != -1) {
id = id.substring(4).trim();
}
if (attachments == null) {
return null;
}
for (Iterator<Attachment> iter = attachments.iterator(); iter.hasNext();) {
Attachment a = iter.next();
if (a.getId().equals(id)) {
return a;
}
}
// Try loading the URL remotely
try {
URLDataSource source = new URLDataSource(new URL(id));
return new AttachmentImpl(id, new DataHandler(source));
} catch (MalformedURLException e) {
return null;
}
}The resulting data handler is then read as the parameter value, so the server connects to the URL. An attacker who can send requests to any Aegis-bound operation can submit an MTOM request with an xop:Include whose href is, for example, http://169.254.169.254/latest/meta-data/ or an internal-only HTTP endpoint. The server then makes the request from its own network position. Depending on how the service uses or echoes the parameter, the fetched content may be returned to the attacker. Nothing in the request path restricts the target, and there is no configuration switch to turn the behavior off.
Mitigation
Only recent versions of Apache CXF receive community support. Older lines are End-of-Life and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Tobias S. Fink (finder)