First published: Fri Aug 03 2018(Updated: )
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ocsinventory-ng ocsinventory NG | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14473 is rated as a medium severity vulnerability due to its potential for information exfiltration and Denial of Service.
To fix CVE-2018-14473, upgrade OCS Inventory to the latest version that addresses the XML parsing configuration issue.
CVE-2018-14473 can be exploited by sending crafted HTTP requests that utilize XML external entities.
Exploiting CVE-2018-14473 may lead to sensitive information disclosure or a Denial of Service condition.
Yes, systems running OCS Inventory version 2.4.1 are vulnerable to CVE-2018-14473 and should be updated immediately.