← Back

CVE-2018-11788

nvd nist
Published: Jan 7, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

Affected (4)

Products: Apache: Karaf
1 product
Karaf
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 4.1.7
From 4.2.0 to 4.2.1
Version 4.2.0 milestone1
Version 4.2.0 milestone2

References (4)

Source: security@apache.org
Vendor Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.