The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.
References
Link | Resource |
---|---|
https://korelogic.com/Resources/Advisories/KL-001-2024-010.txt | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Aug/8 |
Configurations
History
No history.
Information
Published : 2024-08-08 00:15
Updated : 2024-11-21 09:50
NVD link : CVE-2024-6893
Mitre link : CVE-2024-6893
CVE.ORG link : CVE-2024-6893
JSON object : View
Products Affected
journyx
- journyx
CWE
CWE-611
Improper Restriction of XML External Entity Reference