REDHAT-BUG-1508110: SSRF
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
References:
http://www.openwall.com/lists/oss-security/2016/07/12/5 https://0ang3el.blogspot.in/2016/07/beware-of-ws-xmlrpc-library-in-your.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1508110?
The severity of REDHAT-BUG-1508110 is classified as critical due to its potential for server-side request forgery.
How do I fix REDHAT-BUG-1508110?
To fix REDHAT-BUG-1508110, update the Apache XML-RPC library to version 3.1.4 or later which addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-1508110?
The potential impacts of REDHAT-BUG-1508110 include unauthorized access to internal services and data exfiltration through SSRF attacks.
Which products are affected by REDHAT-BUG-1508110?
REDHAT-BUG-1508110 affects the Apache XML-RPC library and Apache Archiva, specifically versions prior to the security patch.
Who can exploit REDHAT-BUG-1508110?
Remote attackers can exploit REDHAT-BUG-1508110 by sending crafted DTD files to conduct SSRF attacks.