An XML External Entity vulnerability was found in vertx-web before 3.5.4. The function isValid didn't provide any XXE protection when parsing an XML document.
Upstream issue:
https://github.com/vert-x3/vertx-web/issues/1021
References:
https://bugs.eclipse.org/bugs/showbug.cgi?id=539568
Upstream patches:
https://github.com/vert-x3/vertx-web/pull/1022/commits/d814d22ade14bafec47c4447a4ba9bff090f05e8 https://github.com/vert-x3/vertx-web/pull/1022/commits/26db16c7b32e655b489d1a71605f9a785f788e41
Eclipse Vert.x before version 3.5.2 does not properly neutralize CR and LF characters in HTTP request before return responses. A remote attacker could exploit this to inject abritrary HTTP response headers to potentially mount cross-site scripting and cache poisoning attacks.
External Reference:
https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-021vertx.txt
Upstream Issue:
https://github.com/eclipse/vert.x/issues/2470
Upstream Patch:
https://github.com/eclipse/vert.x/commit/1bb6445226c39a95e7d07ce3caaf56828e8aab72