CVE Vulnerabilities

CVE-2024-55156

Use of Externally-Controlled Format String

Published: Feb 21, 2025 | Modified: Mar 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Potential Mitigations

References