CVE-2018-1077XML External Entity (XXE) Injection in Spacewalk

Severity
7.5HIGHNVD
EPSS
0.2%
top 55.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 13

Description

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-c447-rp4f-fgvj: Spacewalk 22022-05-13
CVEList
CVE-2018-1077: Spacewalk 22018-03-14

📋Vendor Advisories

1
Red Hat
spacewalk: XML External Entity (XXE) on Spacewalk APIs2018-03-12

💬Community

3
Bugzilla
CVE-2020-1693 spacewalk: XML entity attacks on /rpc/api2020-01-13
Bugzilla
CVE-2017-18594 nmap: denial of service condition due to a double free when SSH connection fails2019-09-05
Bugzilla
CVE-2018-1077 spacewalk: XML External Entity (XXE) on Spacewalk APIs2018-03-14
CVE-2018-1077 — XML External Entity (XXE) Injection | cvebase