CVE-2018-12544

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eclipse:vert.x:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.2:cr1:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.2:cr2:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.2:cr3:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:vert.x:3.5.3:cr1:*:*:*:*:*:*

History

21 Nov 2024, 03:45

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2018:2946 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2018:2946 - Third Party Advisory
References () https://bugs.eclipse.org/bugs/show_bug.cgi?id=539568 - Issue Tracking, Patch, Vendor Advisory () https://bugs.eclipse.org/bugs/show_bug.cgi?id=539568 - Issue Tracking, Patch, Vendor Advisory
References () https://github.com/vert-x3/vertx-web/issues/1021 - Patch, Third Party Advisory () https://github.com/vert-x3/vertx-web/issues/1021 - Patch, Third Party Advisory
References () https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E - () https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E -

07 Nov 2023, 02:52

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E', 'name': '[pulsar-commits] 20201215 [GitHub] [pulsar] yanshuchong opened a new issue #8967: CVSS issue list', 'tags': [], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E -

Information

Published : 2018-10-10 20:29

Updated : 2024-11-21 03:45


NVD link : CVE-2018-12544

Mitre link : CVE-2018-12544

CVE.ORG link : CVE-2018-12544


JSON object : View

Products Affected

eclipse

  • vert.x
CWE
CWE-611

Improper Restriction of XML External Entity Reference