CVE-2018-8038
Last modified
CVE-2018-8038 is a vulnerability of currently unknown severity. Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.. EPSS estimates a 10.73% chance of exploitation in the next 30 days.
Description
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf Fediz | < 1.4.4 |
References
- http://www.securitytracker.com/id/1041220Third Party Advisory, VDB Entry
- https://github.com/apache/cxf-fediz/commit/b6ed9865d0614332fa419fe4b6d0fe81bc2e660dPatch, Third Party Advisory
- http://www.securitytracker.com/id/1041220Third Party Advisory, VDB Entry
- https://github.com/apache/cxf-fediz/commit/b6ed9865d0614332fa419fe4b6d0fe81bc2e660dPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8038?
How severe is CVE-2018-8038?
How do I fix CVE-2018-8038?
Are you affected by CVE-2018-8038?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
