CVE-2018-8038
High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3
EPSS 10.7%
Description
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
How to fix CVE-2018-8038
To remediate CVE-2018-8038, upgrade the affected package to a fixed version below.
- Maven/org.apache.cxf.fediz:fediz-jetty8—upgrade to 1.4.4 or later
- —upgrade to 1.4.4 or later
- —upgrade to 1.4.4 or later
- —upgrade to 1.4.4 or later
- —upgrade to 1.4.4 or later
Is CVE-2018-8038 being exploited?
Moderate — EPSS is 10.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (5)
- from 0, < 1.4.4
- from 0, < 1.4.4
- from 0, < 1.4.4
- from 0, < 1.4.4
- from 0, < 1.4.4