karaf-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jean-Baptiste Onofré ...@nanthrax.net>
Subject [SECURITY] New security advisory for CVE-2018-11788 released for Apache Karaf
Date Sun, 06 Jan 2019 06:23:52 GMT
A new security advisory has been released for Apache Karaf, that is
fixed in recent 4.1.7 and 4.2.2 releases.

CVS-2018-11788: XXE vulnerability found on Apache Karaf

Severity: Moderate

Vendor: The Apache Software Foundation

Versions Affected: all versions of Apache Karaf prior to 4.1.7, 4.2.2.


Apache Karaf provides a features deployer, which allows users to "hot
a features XML by dropping the file directly in the deploy folder.

The features XML is parsed by XMLInputFactory class.

Apache Karaf XMLInputFactory class doesn't contain any mitigation codes
against XXE.
This is a potential security risk as an user can inject external XML

The mitigation is to prevent XXE by disabling external entities loading
in XMLInputFactory and XmlUtils.

This has been fixed in revision:


Mitigation: Apache Karaf users should upgrade to 4.1.7, 4.2.2
or later as soon as possible.

JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-5911

Credit: This issue was reported by Brian Wang.

View raw message