{"id":"GHSA-jxm5-5xcw-h57q","summary":"exist-db:exist-core XML External Entity (XXE) vulnerability","details":"exist version \u003c= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.","aliases":["CVE-2018-1000823"],"modified":"2024-02-19T05:33:45.559912Z","published":"2018-12-20T22:02:17Z","database_specific":{"github_reviewed_at":"2020-06-16T21:44:26Z","nvd_published_at":null,"cwe_ids":["CWE-611"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000823"},{"type":"WEB","url":"https://github.com/eXist-db/exist/issues/2180"},{"type":"WEB","url":"https://github.com/eXist-db/exist/pull/2243"},{"type":"WEB","url":"https://github.com/eXist-db/exist/pull/2247"},{"type":"WEB","url":"https://github.com/eXist-db/exist/commit/1c3f0aec14d00bdbca175713af70cb7c7b868e9f"},{"type":"WEB","url":"https://github.com/eXist-db/exist/commit/b210f9fbf379b68842f2b055dda80d7e7479e96f"},{"type":"WEB","url":"https://0dd.zone/2018/10/27/exist-XXE"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jxm5-5xcw-h57q"},{"type":"PACKAGE","url":"https://github.com/eXist-db/exist"}],"affected":[{"package":{"name":"org.exist-db:exist-core","ecosystem":"Maven","purl":"pkg:maven/org.exist-db/exist-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.0"}]}],"versions":["5.0.0","5.0.0-RC8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-jxm5-5xcw-h57q/GHSA-jxm5-5xcw-h57q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}