CVE-2018-1000823

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References
Link Resource
https://github.com/eXist-db/exist/issues/2180 Issue Tracking Third Party Advisory
https://0dd.zone/2018/10/27/exist-XXE/ Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:exist-db:exist:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc4:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:*:*:*:*:*:*:*:*

Information

Published : 2018-12-20 07:29

Updated : 2019-09-24 06:10


NVD link : CVE-2018-1000823

Mitre link : CVE-2018-1000823


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

exist-db

  • exist