Signal is active with 1 mentions in latest observed window
Immediate actions
Patch apache cxf systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
The post outlines a CTF walk‑through that chains two CVEs (CXF LFI and HoverFly RCE) to achieve root, linking to a full write‑up, but it does not provide exploit code or patch details.
HTB DevArea (retired): a four-layer Linux attack chain walks through CVE-2022-46364 arbitrary file read, Hoverfly CVE-2025-54123 command injection, Flask cookie forgery, and a symlink-chain bypass in a sudo script.
- CVE-2022-46364 (Apache CXF before 3.4.10/3.5.5) lets an attacker embed an xop:Include href="file:///..." element inside a multipart/related MTOM SOAP request. The server fetches the path, base64-encodes the bytes, and reflects them in the response. The employee-service.jar on the anonymous FTP server fingered the vulnerable CXF 3.2.14 version before a packet was sent. Reading /proc/self/cmdline and /proc/[pid]/cmdline exposed the Hoverfly process command line in plaintext, leaking creds: admin:O7IJ27MyyXiU.
- CVE-2025-54123 (Hoverfly 1.11.3): a PUT to /api/v2/hoverfly/middleware with JSON body {"binary":"/bin/bash","script":"..."} passes user-controlled values directly to exec.Command without sanitization. The server runs the script as the service user, giving a shell as dev_ryan. The fix in 1.12.0 disables the middleware API by default.
- The SysWatch Flask app stores its SECRET_KEY in /etc/syswatch.env with chmod 755 (world-readable). Reading that file via the CXF file-read lets an attacker forge a valid Flask session cookie (flask-unsign or Flask's own SecureCookieSessionInterface).
#DFIR_Radar
Post summary
The post details a four‑layer attack chain using CVE‑2022‑46364 and CVE‑2025‑54123, describing file‑read and command‑injection exploitation steps, and notes a mitigation in Hoverfly 1.12.0.