Server-side Request Forgery and File Enumeration in Apache Roller
CVE-2018-17198
What is CVE-2018-17198?
Apache Roller versions 5.2.1, 5.2.0, and earlier unsupported releases are susceptible to a Server-side Request Forgery (SSRF) and File Enumeration vulnerability due to the use of the Java SAX Parser in its XML-RPC interface. By default, this parser permits external entities in XML DOCTYPE declarations, rendering the application vulnerable even if the XML-RPC feature is disabled via the web admin interface. To mitigate this issue, users are advised to upgrade to Apache Roller 5.2.2 or modify the web.xml configuration file to disable the XML-RPC Servlet mapping.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Roller 5.2.1
Apache Roller 5.2.0
Apache Roller earlier unsupported versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved