QID 981595
QID 981595: Java (maven) Security Update for org.apache.olingo:odata-client-core (GHSA-v4qh-6367-4cx2)
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the attacker.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v4qh-6367-4cx2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-v4qh-6367-4cx2 -
github.com/advisories/GHSA-v4qh-6367-4cx2
CVEs related to QID 981595
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v4qh-6367-4cx2 | org.apache.olingo:odata-client-core |
|