CVE-2018-8038

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:cxf_fediz:*:*:*:*:*:*:*:*

History

16 Jun 2021, 12:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E -

Information

Published : 2018-07-05 13:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-8038

Mitre link : CVE-2018-8038

CVE.ORG link : CVE-2018-8038


JSON object : View

Products Affected

apache

  • cxf_fediz
CWE
CWE-20

Improper Input Validation