Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11788

Опубликовано: 06 янв. 2019
Источник: redhat
CVSS3: 7.3
EPSS Средний

Описание

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

A flaw was found in the Apache Karaf XMLInputFactory, where it does not prevent External Entity Processing (XXE). This is a potential security risk as an attacker could inject external XML entities to access sensitive information or conduct further attacks.

Отчет

Red Hat OpenStack Platform: Karaf is used by RHOSP's OpenDaylight, and this flaw impacts the loading of XML documents within Karaf, allowing arbitrary XML to be injected into parsed documents. The impact of this vulnerability is reduced in OpenDaylight, given karaf is an administrative component and not normally exposed to public networks or non-privileged users, and therefore will not be fixed at this time. Fuse 7: The impact of this vulnerability is reduced, as exploiting it would require a authenticated user, and no unsecured endpoints are exposed to the network

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7karafAffected
Red Hat JBoss A-MQ 6karafWill not fix
Red Hat JBoss Fuse 6karafWill not fix
Red Hat JBoss Fuse Service Works 6karafWill not fix
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix
Red Hat OpenStack Platform 14 (Rocky)opendaylightOut of support scope
Red Hat OpenStack Platform 8 (Liberty)opendaylightOut of support scope
Red Hat OpenStack Platform 9 (Mitaka)opendaylightOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1663857karaf: XML external entity processing

EPSS

Процентиль: 96%
0.24747
Средний

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 9.8
debian
около 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot ...

CVSS3: 9.8
github
около 7 лет назад

XML External Entity Reference in Apache Karaf

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость класса XMLInputFactory контейнера OSGi Apache Karaf, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.24747
Средний

7.3 High

CVSS3