CVE-2019-18213
Summary
| CVE | CVE-2019-18213 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-23 22:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eclipse | Wild Web Developer | - | All | All | All |
| Application | Eclipse | Wild Web Developer | - | All | All | All |
| Application | Theia Xml Extension Project | Theia Xml Extension | - | All | All | All |
| Application | Theia Xml Extension Project | Theia Xml Extension | - | All | All | All |
| Application | Xml Language Server Project | Xml Server Project | All | All | All | All |
| Application | Xml Language Server Project | Xml Server Project | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Don't open that XML: XXE to RCE in XML plugins for VS Code, Eclipse, Theia, ... - Shielder | MISC | www.shielder.it | Exploit, Third Party Advisory |
| lemminx/CHANGELOG.md at master · eclipse/lemminx · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Add disallowDocTypeDecl & resolveExternalEntities validation settings by angelozerr · Pull Request #566 · eclipse/lemminx · GitHub | MISC | github.com | Patch, Third Party Advisory |
| GitHub - angelozerr/lsp4xml: XML Language Server | MISC | github.com | Product |
| XML - Visual Studio Marketplace | MISC | marketplace.visualstudio.com | Third Party Advisory |
| GitHub - redhat-developer/vscode-xml: Editing XML in Visual Studio Code made easy | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.