CVE-2018-1000834

runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References
Link Resource
https://github.com/runelite/runelite/issues/6160 Issue Tracking Third Party Advisory
https://0dd.zone/2018/10/28/runelite-XXE-MitM/ Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:runelite:runelite:*:*:*:*:*:*:*:*

Information

Published : 2018-12-20 03:29

Updated : 2019-01-08 07:05


NVD link : CVE-2018-1000834

Mitre link : CVE-2018-1000834

Products Affected
No products.
CWE
CWE-611

Improper Restriction of XML External Entity Reference