PT-2025-27409 · Apache · Apache Eventmesh
Published
2025-06-30
·
Updated
2025-08-20
·
CVE-2024-39954
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Apache EventMesh versions prior to 1.12.0
Description:
This issue is a Server-Side Request Forgery (SSRF) within the
eventmesh-runtime module, specifically in the WebhookUtil.java file, affecting Windows, Linux, and macOS operating systems. The flaw allows an attacker to exploit server functionality to read or update internal resources. SSRF occurs when a server processes user-supplied data in a way that causes it to make requests to unintended locations.Recommendations:
Upgrade to version 1.12.0 or use the master branch to resolve this issue.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Eventmesh