Description
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-92wj-x78c-m4fx | XML External Entity Reference in Apache Karaf |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T08:17:09.240Z
Reserved: 2018-06-05T00:00:00.000Z
Link: CVE-2018-11788
No data.
Status : Modified
Published: 2019-01-07T16:29:00.200
Modified: 2024-11-21T03:44:02.440
Link: CVE-2018-11788
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA