Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11758


This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tricks a user of CayenneModeler into opening a malicious XML file, the attacker will be able to instruct the XML parser built into CayenneModeler to transfer files from a local machine to a remote machine controlled by the attacker. The cause of the issue is XML parser processing XML External Entity (XXE) declarations included in XML. The vulnerability is addressed in Cayenne by disabling XXE processing in all operations that require XML parsing.


Published

2018-08-22T20:29:00.240

Last Modified

2024-11-21T03:43:58.163

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cayenne ≤ 3.1.0 Yes
Application apache cayenne 3.1.1 Yes
Application apache cayenne 3.1.2 Yes
Application apache cayenne 3.2 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.0 Yes
Application apache cayenne 4.1 Yes

References