In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0664 | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema. |
Github GHSA |
GHSA-qh3m-qw6v-qvhg | Moderate severity vulnerability that affects io.vertx:vertx-core |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.199Z
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12544
No data.
Status : Modified
Published: 2018-10-10T20:29:00.710
Modified: 2024-11-21T03:45:24.490
Link: CVE-2018-12544
OpenCVE Enrichment
No data.
EUVD
Github GHSA