Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92wj-x78c-m4fx

Опубликовано: 07 янв. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

XML External Entity Reference in Apache Karaf

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

Пакеты

Наименование

org.apache.karaf.specs:org.apache.karaf.specs.java.xml

maven
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.2

4.2.2

Наименование

org.apache.karaf.specs:org.apache.karaf.specs.java.xml

maven
Затронутые версииВерсия исправления

< 4.1.7

4.1.7

EPSS

Процентиль: 96%
0.24747
Средний

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.3
redhat
около 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 9.8
nvd
около 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 9.8
debian
около 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot ...

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость класса XMLInputFactory контейнера OSGi Apache Karaf, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.24747
Средний

9.8 Critical

CVSS3

Дефекты

CWE-611