CVE-2018-1000834

runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References
Link Resource
https://github.com/runelite/runelite/issues/6160 Issue Tracking Third Party Advisory
https://0dd.zone/2018/10/28/runelite-XXE-MitM/ Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:runelite:runelite:*:*:*:*:*:*:*:*

Information

Published : 2018-12-20 07:29

Updated : 2019-01-08 11:05


NVD link : CVE-2018-1000834

Mitre link : CVE-2018-1000834


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

runelite

  • runelite