CVE-2018-1307
published 2018-02-09CVE-2018-1307: In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…
PriorityP342high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.70%
74.6th percentile
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | juddi | 3.2 – 3.3.4 | — |
| apache_software_foundation | apache_juddi | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache juddi-client vulnerable to XML External Entity (XXE)
ghsa·2018-10-19
CVE-2018-1307 [HIGH] CWE-611 Apache juddi-client vulnerable to XML External Entity (XXE)
Apache juddi-client vulnerable to XML External Entity (XXE)
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
OSV
Apache juddi-client vulnerable to XML External Entity (XXE)
osv·2018-10-19
CVE-2018-1307 [HIGH] Apache juddi-client vulnerable to XML External Entity (XXE)
Apache juddi-client vulnerable to XML External Entity (XXE)
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Red Hat
juddi-client: XML Entity Expansion in WADL2Java or WSDL2Java classes
vendor_redhat·2017-11-10·CVSS 8.1
CVE-2018-1307 [HIGH] CWE-776 juddi-client: XML Entity Expansion in WADL2Java or WSDL2Java classes
juddi-client: XML Entity Expansion in WADL2Java or WSDL2Java classes
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Statement: No Red Hat products are affected by CVE-2018-1307.
Package: juddi-client (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: juddi-client (Red Hat JBoss Fuse 6) - Not affected
Package: juddi-client (Red Hat JBoss Operations Network 3) - Not affected
Package: juddi-client (Red Hat JBoss Portal 6) - Not affected
Package: juddi-client (Red Hat JBoss SOA Platform 5) - Not affected
No detection rules found.
No public exploits indexed.
2018-02-09
Published