CVE-2018-1000546
Last modified
CVE-2018-1000546 is a vulnerability of currently unknown severity. Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).. EPSS estimates a 2.57% chance of exploitation in the next 30 days.
Description
Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Triplea-Game | Triplea | <= 1.9.0.0.10291 |
References
- https://0dd.zone/2018/05/31/TripleA-XXE/Exploit, Third Party Advisory
- https://github.com/triplea-game/triplea/issues/3442Exploit, Third Party Advisory
- https://0dd.zone/2018/05/31/TripleA-XXE/Exploit, Third Party Advisory
- https://github.com/triplea-game/triplea/issues/3442Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000546?
How severe is CVE-2018-1000546?
How do I fix CVE-2018-1000546?
Are you affected by CVE-2018-1000546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
