CVE-2018-1307
Summary
| CVE | CVE-2018-1307 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-09 19:29:00 UTC |
| Updated | 2018-03-08 16:36:00 UTC |
| Description | In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache jUDDI – Security Advisories | CONFIRM | juddi.apache.org | Vendor Advisory |
| [JUDDI-987] CVE-2018-1307 XML Entity Expansion - ASF JIRA | CONFIRM | issues.apache.org | Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980962 Java (maven) Security Update for org.apache.juddi:juddi-client (GHSA-p99p-726h-c8v5)