// For flags

CVE-2018-12544

vertx: API Validation XML Schemas do not forbid file system access

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.

De la versiĆ³n 3.5.Beta1 a la 3.5.3 de Eclipse Vert.x, el validador de tipos XML OpenAPI crea analizadores XML sin las medidas defensivas adecuadas contra ataques XML. Este mecanismo es exclusivo a cuando el desarrollador emplea el validador de tipos XML OpenAPI de Eclipse Vert.x para validar un esquema proporcionado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-06-18 CVE Reserved
  • 2018-10-10 CVE Published
  • 2024-07-25 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.0
Search vendor "Eclipse" for product "Vert.x" and version "3.5.0"
-
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.0
Search vendor "Eclipse" for product "Vert.x" and version "3.5.0"
beta1
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.1
Search vendor "Eclipse" for product "Vert.x" and version "3.5.1"
-
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.2
Search vendor "Eclipse" for product "Vert.x" and version "3.5.2"
-
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.2
Search vendor "Eclipse" for product "Vert.x" and version "3.5.2"
cr1
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.2
Search vendor "Eclipse" for product "Vert.x" and version "3.5.2"
cr2
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.2
Search vendor "Eclipse" for product "Vert.x" and version "3.5.2"
cr3
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.3
Search vendor "Eclipse" for product "Vert.x" and version "3.5.3"
-
Affected
Eclipse
Search vendor "Eclipse"
Vert.x
Search vendor "Eclipse" for product "Vert.x"
3.5.3
Search vendor "Eclipse" for product "Vert.x" and version "3.5.3"
cr1
Affected