In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2018:2946 | Third Party Advisory |
https://bugs.eclipse.org/bugs/show_bug.cgi?id=539568 | Issue Tracking Patch Vendor Advisory |
https://github.com/vert-x3/vertx-web/issues/1021 | Patch Third Party Advisory |
https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: eclipse
Published: 2018-10-10T20:00:00
Updated: 2020-12-16T05:06:24
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12544
JSON object: View
NVD Information
Status : Modified
Published: 2018-10-10T20:29:00.710
Modified: 2023-11-07T02:52:20.350
Link: CVE-2018-12544
JSON object: View
Redhat Information
No data.
CWE