PT-2025-27409 · Apache · Apache Eventmesh

Published

2025-06-30

·

Updated

2025-08-20

·

CVE-2024-39954

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Apache EventMesh versions prior to 1.12.0
Description: This issue is a Server-Side Request Forgery (SSRF) within the eventmesh-runtime module, specifically in the WebhookUtil.java file, affecting Windows, Linux, and macOS operating systems. The flaw allows an attacker to exploit server functionality to read or update internal resources. SSRF occurs when a server processes user-supplied data in a way that causes it to make requests to unintended locations.
Recommendations: Upgrade to version 1.12.0 or use the master branch to resolve this issue.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39954
GHSA-HF86-8X8V-H7VC

Affected Products

Apache Eventmesh