← Back

CVE-2018-12544

nvd nist
Published: Oct 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.

Affected (9)

Products: Eclipse: Vert.x
1 product
Vert.x
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
Version 3.5.0
Version 3.5.0 beta1
Version 3.5.1
Version 3.5.2
Version 3.5.2 cr1
Version 3.5.2 cr2
Version 3.5.2 cr3
Version 3.5.3
Version 3.5.3 cr1

References (8)

Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Issue TrackingPatchVendor Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.