SB2018042513 - Denial of service in WireMock
Published: April 25, 2018
Security Bulletin ID
SB2018042513
CSH Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) XXE attack (CVE-ID: CVE-2018-9116)
CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists due to the inclusion of remote Document Type Definition (DTD) documents when using XPath or XML matching. A remote attacker can send a specially crafted request, trigger CPU saturation and cause the service to crash.
Remediation
Install update from vendor's website.