{"id":"CVE-2018-17198","details":"Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. Note that this vulnerability exists even if Roller XML-RPC interface is disable via the Roller web admin UI. Mitigation: There are a couple of ways you can fix this vulnerability: 1) Upgrade to the latest version of Roller, which is now 5.2.2 2) Or, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping as shown below: \u003c!-- \u003cservlet-mapping\u003e \u003cservlet-name\u003eXmlRpcServlet\u003c/servlet-name\u003e \u003curl-pattern\u003e/roller-services/xmlrpc\u003c/url-pattern\u003e \u003c/servlet-mapping\u003e --\u003e","modified":"2026-07-08T05:54:25.997201108Z","published":"2019-05-28T18:29:00.273Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:apache:roller:5.2.0:rc2:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.0:rc3:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.0:rc4:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.0:rc5:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.0:rc6:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.2.0-rc2"},{"last_affected":"5.2.0-rc2"},{"introduced":"5.2.0-rc3"},{"last_affected":"5.2.0-rc3"},{"introduced":"5.2.0-rc4"},{"last_affected":"5.2.0-rc4"},{"introduced":"5.2.0-rc5"},{"last_affected":"5.2.0-rc5"},{"introduced":"5.2.0-rc6"},{"last_affected":"5.2.0-rc6"}],"source":"CPE_STRING","vendor_product":"apache:roller"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/94a36ed9c6241558b1c6181d8dd4ff263be7903abd1d20067d4330d5%40%3Cdev.roller.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/108496"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/roller","events":[{"introduced":"0"},{"last_affected":"1b6cf8b2234b279d2f6bfe121693161c15d3e501"},{"introduced":"25a9bc7fb4fab505f770ead07fb26634c5465def"},{"last_affected":"0a8b286525c81b8634b47c848aa738b693f4b93a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.1.2"},{"introduced":"5.2.0-NA"},{"last_affected":"5.2.0-NA"},{"introduced":"5.2.1"},{"last_affected":"5.2.1"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:apache:roller:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.0:-:*:*:*:*:*:*","cpe:2.3:a:apache:roller:5.2.1:*:*:*:*:*:*:*"]}}],"versions":["5.2.0-NA","5.2.1","roller-5.2.1-rc-2","roller-5.2.1","roller-5.2.10-rc-1","roller-5.2.0","roller-5.2.0-rc-6","roller-5.2.0-rc-5","roller-5.2.0-rc-4","roller-5.2.0-rc-3","roller-5.2.0-rc-2","roller-5.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-17198.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}