Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28168

Опубликовано: 09 окт. 2024
Источник: redhat
CVSS3: 7.5

Описание

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

A flaw was found in Apache XML Graphics FOP. This vulnerability allows remote attackers to cause issues via improper handling of XML External Entity (XXE) references.

Отчет

The XXE vulnerability in Apache XML Graphics FOP is considered important rather than moderate due to its potential to compromise the confidentiality, integrity, and availability of a system. XXE flaws can be exploited to access sensitive internal files, such as configuration or credential files, leading to data exposure without authorization. Additionally, XXE attacks may enable attackers to perform server-side request forgery (SSRF), allowing them to make unauthorized requests to internal systems or services, potentially pivoting within a network. Red Hat build of Apache Camel for Springboot ships the affected component but it is not a supported library, hence the will not fix state.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3org.apache.xmlgraphics/fopNot affected
Red Hat build of Apache Camel for Spring Boot 4org.apache.xmlgraphics/fopNot affected
Red Hat build of OptaPlanner 8org.apache.xmlgraphics/fopNot affected
Red Hat Fuse 7org.apache.xmlgraphics/fopWill not fix
Red Hat Integration Camel K 1org.apache.xmlgraphics/fopWill not fix
Red Hat JBoss Data Grid 7org.apache.xmlgraphics/fopNot affected
Red Hat JBoss Enterprise Application Platform 7org.apache.xmlgraphics/fopNot affected
Red Hat JBoss Enterprise Application Platform 8org.apache.xmlgraphics/fopNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.apache.xmlgraphics/fopNot affected
Red Hat Process Automation 7org.apache.xmlgraphics/fopNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2317557fop: Improper Restriction of XML External Entity Reference ('XXE')

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
nvd
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
debian
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerab ...

suse-cvrf
7 месяцев назад

Security update for javapackages-tools, xmlgraphics-batik, xmlgraphics-commons, xmlgraphics-fop

CVSS3: 5.3
github
8 месяцев назад

Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability

7.5 High

CVSS3