GHSA-rmqp-9w4c-gc7w
CRITICALCVE-2023-40743When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE.
- Affected
- <= 1.4
- Fixed in
- not stated
- Weakness
- CWE-20
- Published
- 2023-09-05
- Source
- github