CVE-2018-11788

Severity
9.8CRITICAL
EPSS
24.7%
top 3.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7

Description

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/karaf4.2.04.2.1+2
CVEListV5apache_software_foundation/apache_karafAny Apache Karaf version prior to 4.1.7 and 4.2.2

🔴Vulnerability Details

3
OSV
XML External Entity Reference in Apache Karaf2019-01-07
GHSA
XML External Entity Reference in Apache Karaf2019-01-07
CVEList
CVE-2018-11788: Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder2019-01-07

📋Vendor Advisories

1
Red Hat
karaf: XML external entity processing2019-01-06

💬Community

1
Bugzilla
CVE-2018-11788 karaf: XML external entity processing2019-01-07
CVE-2018-11788 (CRITICAL CVSS 9.8) | Apache Karaf provides a features de | cvebase.io