CVE Vulnerabilities

CVE-2018-1000546

Improper Restriction of XML External Entity Reference

Published: Jun 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Triplea Triplea-game * 1.9.0.0.10291 (including)
Triplea Ubuntu artful *
Triplea Ubuntu bionic *
Triplea Ubuntu cosmic *
Triplea Ubuntu disco *
Triplea Ubuntu eoan *
Triplea Ubuntu focal *
Triplea Ubuntu groovy *
Triplea Ubuntu hirsute *
Triplea Ubuntu impish *
Triplea Ubuntu kinetic *
Triplea Ubuntu lunar *
Triplea Ubuntu mantic *
Triplea Ubuntu oracular *
Triplea Ubuntu trusty *
Triplea Ubuntu xenial *

Potential Mitigations

References