{"id":"GHSA-hr2c-p8rh-238h","summary":"Apache Axis Improper Input Validation vulnerability","details":"** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF.\nThis issue affects Apache Axis through 1.3.\n\nAs Axis 1 has been EOL, we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. Alternatively you could use a build of Axis with the patch from https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06 applied. The Apache Axis project does not expect to create an Axis 1.x release \nfixing this problem, though contributors that would like to work towards this are welcome.","aliases":["CVE-2023-51441"],"modified":"2024-03-14T22:01:29.539084Z","published":"2024-01-06T12:30:34Z","database_specific":{"cwe_ids":["CWE-20","CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-08T15:49:03Z","nvd_published_at":"2024-01-06T12:15:42Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-51441"},{"type":"WEB","url":"https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06"},{"type":"PACKAGE","url":"https://github.com/apache/axis-axis1-java"},{"type":"WEB","url":"https://lists.apache.org/thread/8nrm5thop8f82pglx4o0jg8wmvy6d9yd"}],"affected":[{"package":{"name":"org.apache.axis:axis","ecosystem":"Maven","purl":"pkg:maven/org.apache.axis/axis"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-hr2c-p8rh-238h/GHSA-hr2c-p8rh-238h.json"}},{"package":{"name":"axis:axis","ecosystem":"Maven","purl":"pkg:maven/axis/axis"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3"}]}],"versions":["1.0","1.1","1.1-beta","1.2","1.2-RC1","1.2-RC2","1.2-RC3","1.2-alpha-1","1.2-beta-2","1.2-beta-3","1.2.1","1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-hr2c-p8rh-238h/GHSA-hr2c-p8rh-238h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}