CVE-2018-1000823
Summary
| CVE | CVE-2018-1000823 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-20 15:29:00 UTC |
| Updated | 2019-09-24 13:10:00 UTC |
| Description | exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Exist XXE | 0dd - The Zero (0) Day Division |
MISC |
0dd.zone |
Third Party Advisory |
| XXE in RESTServer.java · Issue #2180 · eXist-db/exist · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982311 Java (maven) Security Update for org.exist-db:exist-core (GHSA-jxm5-5xcw-h57q)