CVE-2018-1309
published 2018-05-23CVE-2018-1309: Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to…
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.52%
90.5th percentile
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | < 1.6.0 | 1.6.0 |
| apache | nifi | — | — |
| apache_software_foundation | apache_nifi | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv3.3LOW
vendor_apache9.8
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache nifi: CVE-2018-1309
vendor_apache·CVSS 9.8
CVE-2018-1309 Apache nifi: CVE-2018-1309
Apache nifi: CVE-2018-1309
Title: Improper Restriction of XML External Entity References in SplitXml Published: 2018-04-08 Severity: Medium Products: Apache NiFi Affected Versions: 0.1.0 to 1.5.0 Fixed Versions: 1.6.0 Reporter: 圆珠笔 References CVE Record: CVE-2018-1309 NVD Record: CVE-2018-1309 Apache Jira Issue: NIFI-4869 GitHub Pull Request: 2466 Malicious XML content could cause information disclosure or remote code execution in the SplitXml Processor. NiFi 1.6.0 disables external general entity parsing and disallows document type declarations in SplitXml. Users running a prior release should upgrade to 1.6.0.
Severity: moderate
GHSA
Improper Restriction of XML External Entity Reference in Apache NiFi
ghsa·2022-05-14
CVE-2018-1309 [CRITICAL] CWE-611 Improper Restriction of XML External Entity Reference in Apache NiFi
Improper Restriction of XML External Entity Reference in Apache NiFi
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
OSV
Improper Restriction of XML External Entity Reference in Apache NiFi
osv·2022-05-14
CVE-2018-1309 [CRITICAL] Improper Restriction of XML External Entity Reference in Apache NiFi
Improper Restriction of XML External Entity Reference in Apache NiFi
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-05-23
Published