CVE-2018-1000834

runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References
Link Resource
https://0dd.zone/2018/10/28/runelite-XXE-MitM/ Third Party Advisory
https://github.com/runelite/runelite/issues/6160 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:runelite:runelite:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-12-20 15:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-1000834

Mitre link : CVE-2018-1000834

CVE.ORG link : CVE-2018-1000834


JSON object : View

Products Affected

runelite

  • runelite
CWE
CWE-611

Improper Restriction of XML External Entity Reference