PT-2021-8694 · Red Hat · Redhat-Certification

Riccardo Schirone

·

Published

2021-05-26

·

Updated

2023-02-10

·

CVE-2018-10868

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions redhat-certification version 7
Description The issue allows an unauthenticated user to perform a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of a host, due to the improper restriction of recursive definitions of entities in XML documents.
Recommendations For redhat-certification version 7, consider restricting or disabling the XMLRPC methods to minimize the risk of exploitation until a proper fix is available.

Fix

XML Entity Expansion

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2018-10868

Affected Products

Redhat-Certification