Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2018-11788

больше 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2018-11788

больше 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-11788

больше 7 лет назад

Apache Karaf provides a features deployer, which allows users to "hot ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-92wj-x78c-m4fx

больше 7 лет назад

XML External Entity Reference in Apache Karaf

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2019-04862

больше 7 лет назад

Уязвимость класса XMLInputFactory контейнера OSGi Apache Karaf, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-11788

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 7.3
7%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-11788

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS3: 9.8
7%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-11788

Apache Karaf provides a features deployer, which allows users to "hot ...

CVSS3: 9.8
7%
Низкий
больше 7 лет назад
github логотип
GHSA-92wj-x78c-m4fx

XML External Entity Reference in Apache Karaf

CVSS3: 9.8
7%
Низкий
больше 7 лет назад
fstec логотип
BDU:2019-04862

Уязвимость класса XMLInputFactory контейнера OSGi Apache Karaf, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
7%
Низкий
больше 7 лет назад

Уязвимостей на страницу