Vulnerability Description
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf Fediz | < 1.4.4 |
Related Weaknesses (CWE)
References
- http://cxf.apache.org/security-advisories.data/CVE-2018-8038.txt.ascVendor Advisory
- http://www.securitytracker.com/id/1041220Third Party AdvisoryVDB Entry
- https://github.com/apache/cxf-fediz/commit/b6ed9865d0614332fa419fe4b6d0fe81bc2e6PatchThird Party Advisory
- https://lists.apache.org/thread.html/f0a6a05ec3b3a00458da43712b0ff3a2f573175d9bf
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de10
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fd
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba7
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a7
- http://cxf.apache.org/security-advisories.data/CVE-2018-8038.txt.ascVendor Advisory
- http://www.securitytracker.com/id/1041220Third Party AdvisoryVDB Entry
- https://github.com/apache/cxf-fediz/commit/b6ed9865d0614332fa419fe4b6d0fe81bc2e6PatchThird Party Advisory
- https://lists.apache.org/thread.html/f0a6a05ec3b3a00458da43712b0ff3a2f573175d9bf
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de10
FAQ
What is CVE-2018-8038?
CVE-2018-8038 is a vulnerability with a CVSS score of 7.5 (HIGH). Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Pro...
How severe is CVE-2018-8038?
CVE-2018-8038 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-8038?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf Fediz.