Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000069

Опубликовано: 13 мар. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.5

Описание

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.6.6-1
cosmic

ignored

end of life
devel

not-affected

1.6.6-1
disco

not-affected

1.6.6-1
eoan

not-affected

1.6.6-1
esm-apps/bionic

not-affected

1.6.6-1
esm-apps/focal

not-affected

1.6.6-1
esm-apps/jammy

not-affected

1.6.6-1
esm-apps/noble

not-affected

1.6.6-1

Показывать по

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 8 лет назад

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

CVSS3: 5.5
debian
почти 8 лет назад

FreePlane version 1.5.9 and earlier contains a XML External Entity (XX ...

CVSS3: 5.5
github
больше 3 лет назад

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

4.3 Medium

CVSS2

5.5 Medium

CVSS3