CVE Vulnerabilities

CVE-2024-34581

Server-Side Request Forgery (SSRF)

Published: Jun 26, 2024 | Modified: Jul 03, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a RetrievalMethod is a URI … that may be used to obtain key and/or certificate information statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

References