V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-11788
DEB
HighConfirmedExploit available

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy fo…

CVSS
7.3
High
EPSS
0.25
p96
Published
2018-01-01
Updated
2018-01-01
Description

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

Tags · CWE
Pre-auth
CWE-611
CAPEC-221
Affected products
Karaf < 4.1.7Karaf 4.2.0–4.2.1Karaf
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.247 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2018-11788
github-poc · https://github.com/brianwrf/CVE-2018-11788
Enterprise
Affected software
ProductVendorStatus
apache-karafTracked
karaf*Tracked
Source databases
DEB
CVE
Related vulnerabilities