PT-2019-9409 · Apache · Apache Roller

Arseniy Sharoglazov

·

Published

2019-05-28

·

Updated

2019-06-11

·

CVE-2018-17198

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Roller versions 5.2.1, 5.2.0 and earlier
Description The issue is related to Server-side Request Forgery (SSRF) and File Enumeration vulnerability. It relies on the Java SAX Parser, which supports external entities in XML DOCTYPE by default, making Apache Roller vulnerable to SSRF and File Enumeration attacks. This vulnerability exists even if the Roller XML-RPC interface is disabled via the Roller web admin UI.
Recommendations For Apache Roller versions 5.2.1, 5.2.0 and earlier, upgrade to the latest version, which is 5.2.2. Alternatively, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping, specifically the XmlRpcServlet with the url-pattern /roller-services/xmlrpc.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17198

Affected Products

Apache Roller