8.1

CVE-2018-11758

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tricks a user of CayenneModeler into opening a malicious XML file, the attacker will be able to instruct the XML parser built into CayenneModeler to transfer files from a local machine to a remote machine controlled by the attacker. The cause of the issue is XML parser processing XML External Entity (XXE) declarations included in XML. The vulnerability is addressed in Cayenne by disabling XXE processing in all operations that require XML parsing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Cayenne Version <= 3.1.0
Apache ≫ Cayenne Version 3.1.1
Apache ≫ Cayenne Version 3.1.2
Apache ≫ Cayenne Version 3.2 Update milestone1
Apache ≫ Cayenne Version 4.0 Update beta1
Apache ≫ Cayenne Version 4.0 Update beta2
Apache ≫ Cayenne Version 4.0 Update milestone2
Apache ≫ Cayenne Version 4.0 Update milestone3
Apache ≫ Cayenne Version 4.0 Update milestone4
Apache ≫ Cayenne Version 4.0 Update milestone5
Apache ≫ Cayenne Version 4.0 Update rc1
Apache ≫ Cayenne Version 4.1 Update milestone1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.97% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://www.securityfocus.com/bid/105142
Third Party Advisory
VDB Entry
https://lists.apache.org/thread.html/ed60a4d329be3c722f105317ca883986dfcd17615c70d1df87f4528c%40%3Cuser.cayenne.apache.org%3E