PT-2025-7443 · Unknown · Java Sdk For Cloudevents

Published

2025-02-21

·

Updated

2025-02-21

·

CVE-2024-55156

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Java SDK for CloudEvents version 4.0.1
Description The issue is related to an XML External Entity (XXE) vulnerability in the deserializeArgs() method. This allows attackers to access sensitive information by supplying a crafted XML-formatted event message.
Recommendations For Java SDK for CloudEvents version 4.0.1, consider disabling the deserializeArgs() method until a patch is available to prevent exploitation of this issue. Restrict access to sensitive information and avoid using the vulnerable method to deserialize event messages from untrusted sources.

Exploit

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2024-55156

Affected Products

Java Sdk For Cloudevents