PT-2019-11538 · Ladon · Ladon

Published

2019-07-18

·

Updated

2019-07-26

·

CVE-2019-1010268

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ladon versions 0.6.1 and later
Description: The issue affects the SOAP request handlers component, allowing for XML External Entity (XXE) attacks. This can lead to information disclosure, enabling attackers to read files and access internal network endpoints. The attack vector involves sending a specially crafted SOAP call.
Recommendations: For versions 0.6.1 and later, consider disabling the SOAP request handlers until a patch is available to prevent exploitation. Restrict access to internal network endpoints to minimize the risk of information disclosure. Avoid using the affected SOAP interface until the issue is resolved.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010268
GHSA-VG35-VC9F-Q7X2
PYSEC-2019-184

Affected Products

Ladon