CVE-2018-12544
Summary
| CVE | CVE-2018-12544 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-10 20:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| 539568 – (CVE-2018-12544) The OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks |
CONFIRM |
bugs.eclipse.org |
Issue Tracking, Patch, Vendor Advisory |
| API Validation XML Schemas do not forbid file system access (XXE) · Issue #1021 · vert-x3/vertx-web · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983169 Java (maven) Security Update for io.vertx:vertx-core (GHSA-qh3m-qw6v-qvhg)