← Voltar para CVEs
CVE-2026-42404
MEDIUM6.5
Descricao
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Detalhes CVE
Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado5/1/2026
Ultima modificacao5/1/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
apache:neethi
Fraquezas (CWE)
CWE-918
Referencias
https://lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oq(security@apache.org)
http://www.openwall.com/lists/oss-security/2026/05/01/8(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.