CVE-2024-39954
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
20/08/2025
Last modified:
21/08/2025
Description
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read or update internal resources.<br />
Users are recommended to upgrade to version 1.12.0 or use the master branch , which fixes this issue.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:eventmesh:*:*:*:*:*:*:*:* | 1.12.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page