PT-2019-15280 · Red Hat · Xml Language Server+1

Publicado

2019-10-23

·

Atualizado

2021-07-21

·

CVE-2019-18213

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XML Language Server versions prior to 0.9.1 Red Hat XML Language Support versions prior to 0.9.1
Description The issue allows for XXE (XML External Entity) attacks via a crafted XML document. This can result in SSRF (Server-Side Request Forgery) and the initiation of SMB connections, potentially leading to the capture of NetNTLM challenge/response for password cracking.
Recommendations For XML Language Server versions prior to 0.9.1, update to version 0.9.1 or later. For Red Hat XML Language Support versions prior to 0.9.1, update to version 0.9.1 or later.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18213

Produtos afetados

Red Hat Xml Language Support
Xml Language Server