PT-2024-10160 · Http4K · Http4K
Jacklosingheart
·
Published
2024-12-11
·
Updated
2025-05-03
·
CVE-2024-55875
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
http4k versions prior to 5.41.0.0
Description
The issue is related to an XXE (XML External Entity Injection) vulnerability when http4k handles malicious XML contents within requests. This could allow attackers to read local sensitive information on the server, trigger Server-side Request Forgery, and even execute code under some circumstances.
Recommendations
To resolve the issue, update to version 5.41.0.0 or later, as this version contains a patch for the problem.
As a temporary workaround, consider disabling the XML parsing feature in http4k until a patch is applied.
Restrict access to the XML handling module to minimize the risk of exploitation.
Avoid using the
xmlLens function in the affected API endpoint until the issue is resolved.Exploit
Fix
Information Disclosure
SSRF
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Http4K