CVE-2018-11788
Dashboard / Vulnerabilities / CVE-2018-11788
Summary:
Details: Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
References: http://karaf.apache.org/security/cve-2018-11788.txt, http://www.securityfocus.com/bid/106479
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
4.2.0-milestone1
4.2.0-milestone2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
