CVE-2018-1000823

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References
Link Resource
https://github.com/eXist-db/exist/issues/2180 Issue Tracking Third Party Advisory
https://0dd.zone/2018/10/27/exist-XXE/ Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:exist-db:exist:*:*:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:exist-db:exist:5.0.0:rc4:*:*:*:*:*:*

Information

Published : 2018-12-20 03:29

Updated : 2019-09-24 01:10


NVD link : CVE-2018-1000823

Mitre link : CVE-2018-1000823

Products Affected
No products.
CWE
CWE-611

Improper Restriction of XML External Entity Reference