V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-1000632
DEB
Medium

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute th…

CVSS
5.3
Medium
EPSS
0.02
p81
Published
2018-01-01
Updated
2018-01-01
Description

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Tags · CWE
Pre-auth
CWE-88
CWE-91
CAPEC-41
CAPEC-83
CAPEC-88
CAPEC-137
CAPEC-174
CAPEC-250
CAPEC-460
Affected products
Ansible-runnerAnsible-runnerAnsiblerole-foreman_scap_clientAnsiblerole-foreman_scap_clientAnsiblerole-insights-clientAnsiblerole-insights-clientApache-cxfApache-cxfApache-cxfCandlepinCandlepinCreaterepo_cCreaterepo_cDom4jDom4jDom4jDom4jDom4jDom4jDom4j
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.016 · p81
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
ansible-runnerTracked
ansible-runnerTracked
ansiblerole-foreman_scap_clientTracked
ansiblerole-foreman_scap_clientTracked
ansiblerole-insights-clientTracked
ansiblerole-insights-clientTracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
candlepinTracked
candlepinTracked
createrepo_cTracked
createrepo_cTracked
dom4jTracked
dom4jTracked
dom4jTracked
dom4jTracked
dom4jTracked
dom4jTracked
dom4jTracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities