CVE-2024-55156 Details
Description
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
A vulnerability allowing XML External Entity (XXE) injection has been identified in the Java SDK for CloudEvents, version 4.0.1. This vulnerability arises in the 'deserializeArgs()' method, where attackers can exploit the 'deserialize()' method to read sensitive file information by sending crafted XML-formatted event messages. The issue stems from improper handling of XML input, which allows external entities to be defined and processed, potentially leading to unauthorized access to file contents.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 21, 2025CISA-ADP
Assessed Feb 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aixiao0621/CVE/blob/main/CVE-2024-55156/README.md | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| CloudEvents Java SDK | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2025 | CVE Modified | CISA-ADP |
| Feb 21, 2025 | New CVE Received | [email protected] |
Volerion