CVE Vulnerabilities

CVE-2024-55156

Use of Externally-Controlled Format String

Published: Feb 21, 2025 | Modified: Mar 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Potential Mitigations

References