XML External Entity injection in expat - CVE-2018-20843
Published: June 27, 2019 / Updated: June 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input including XML names that contain a large number of colons. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
mingw-expat (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
expat (Alpine package)
expat (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6750B Fibre Channel Switch
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
Brocade Fabric OS
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Data Computing Appliance (DCA)
Dell PowerProtect Cyber Recovery
Ansible Automation Platform
Tenable Nessus
Oracle WebLogic Server Proxy Plug-In
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM API Connect
Oracle Hospitality RES 3700
Oracle Outside In Technology
NetWorker Management Console
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Red Hat OpenShift Container Platform
How to mitigate CVE-2018-20843
mingw-expat (Red Hat package) - update to 2.2.4-5.el8
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
expat (Alpine package) - update to 2.2.7-r0
expat (Red Hat package) - addressed in versions 2.1.0-12.el7, 2.2.5-4.el8
expat (Debian package) - update to 2.2.0-2+deb9u2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.3
IBM API Connect - update to 5.0.8.12
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
Tenable Nessus - update to 8.15.0
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
expat - addressed in versions 2.2.7-1.fc29, 2.2.7-1.fc30
Red Hat OpenShift Container Platform - update to 4.3.40
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
NetWorker Management Console - update to 19.12.0.1
External References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5226
- https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes
- https://github.com/libexpat/libexpat/issues/186
- https://github.com/libexpat/libexpat/pull/262
- https://github.com/libexpat/libexpat/pull/262/commits/11f8838bf99ea0a6f0b76f9760c43704d00c4ff6
- https://usn.ubuntu.com/4040-1/
- https://usn.ubuntu.com/4040-2/
Related Security Bulletins
- XXE in expat library
- Debian update for expat
- OpenSUSE Linux update for expat
- Gentoo update for Expat
- Multiple vulnerabilities in Oracle Outside In Technology
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3
- XML External Entity injection in expat (Alpine package)
- Red Hat Enterprise Linux 7 update for expat
- Red Hat Enterprise Linux 8 update for mingw-expat
- Red Hat Enterprise Linux 8 update for expat
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- XML External Entity injection in Oracle Hospitality RES 3700
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Tenable Nessus
- XML External Entity injection in Oracle WebLogic Server Proxy Plug-In
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in HPE Brocade Fabric OS
- Ubuntu update for libxmltok
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 30 update for expat
- Fedora 29 update for expat
- Dell NetWorker Management Console update for third-party components