CVE-2018-20000: XEE
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-20000.
What is the title of this vulnerability?
The title of this vulnerability is 'Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks as demonstrated by an invite-reply document that reads a local file'.
What does the vulnerability allow?
This vulnerability allows XXE attacks, as demonstrated by an invite-reply document that reads a local file.
What is the affected software?
The affected software is Apereo Bw-webdav up to version 4.0.3.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.5.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-611.
How can I fix this vulnerability?
To fix this vulnerability, upgrade to version 4.0.3 of Apereo Bw-webdav.