XML External Entity Vulnerability in JabRef by JabRef Team
CVE-2018-1000652

10CRITICAL

Key Information:

Vendor

Jabref

Status
Vendor
CVE Published:
20 August 2018

What is CVE-2018-1000652?

JabRef versions up to 4.3.1 are susceptible to an XML External Entity (XXE) vulnerability in the MsBibImporter XML Parser. This vulnerability may allow attackers to craft specific MsBib files to facilitate the disclosure of confidential information, lead to denial of service, and execute server-side request forgery or port scanning. Users are encouraged to upgrade to the patched versions following commit 89f855d to mitigate these security risks.

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.