Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.vertx/vertx-core
  4. ›
  5. CVE-2018-12544

CVE-2018-12544: Improper Restriction of XML External Entity Reference

October 17, 2018 (updated January 8, 2021)

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.

References

  • github.com/advisories/GHSA-qh3m-qw6v-qvhg
  • github.com/vert-x3/vertx-web/issues/1021
  • nvd.nist.gov/vuln/detail/CVE-2018-12544

Code Behaviors & Features

Detect and mitigate CVE-2018-12544 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.5.0 before 3.5.4

Fixed versions

  • 3.5.4

Solution

Upgrade to version 3.5.4 or above.

Impact 9.8 CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

maven/io.vertx/vertx-core/CVE-2018-12544.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:06 +0000.