Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.
References
Link | Resource |
---|---|
https://0dd.zone/2018/08/05/rdf4j-XXE/ | Third Party Advisory |
https://github.com/eclipse/rdf4j/issues/1056 | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:21:58
Updated: 2022-10-03T16:21:58
Reserved: 2018-08-08T00:00:00
Link: CVE-2018-1000644
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-08-20T19:31:39.777
Modified: 2018-11-01T16:21:44.287
Link: CVE-2018-1000644
JSON object: View
Redhat Information
No data.
CWE