XML External Entity Vulnerability in Stroom by GCHQ
CVE-2018-1000651

10CRITICAL

Key Information:

Vendor

Gchq

Status
Vendor
CVE Published:
20 August 2018

What is CVE-2018-1000651?

The Stroom software prior to version 5.4.5 is susceptible to an XML External Entity (XXE) vulnerability. This security flaw occurs in the XML parser that could allow an attacker to exploit specially crafted XML files. The vulnerability can lead to serious security risks such as the disclosure of sensitive information, denial of service attacks, server-side request forgery, and unauthorized network scanning. Organizations using affected versions should urgently assess their exposure and implement necessary security measures.

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.