XML External Entity injection in expat - CVE-2018-20843

 

XML External Entity injection in expat - CVE-2018-20843

Published: June 27, 2019 / Updated: June 20, 2021


Vulnerability identifier: #VU18923
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20843
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input including XML names that contain a large number of colons. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

expat
mingw-expat (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
expat (Alpine package)
expat (Red Hat package)
expat (Debian package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
expat
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6750B Fibre Channel Switch
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
Brocade Fabric OS
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Data Computing Appliance (DCA)
Dell PowerProtect Cyber Recovery
Ansible Automation Platform
Tenable Nessus
Oracle WebLogic Server Proxy Plug-In
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM API Connect
Oracle Hospitality RES 3700
Oracle Outside In Technology
NetWorker Management Console
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Red Hat OpenShift Container Platform

How to mitigate CVE-2018-20843

Install updates from vendor's website.

expat - update to 2.2.7
mingw-expat (Red Hat package) - update to 2.2.4-5.el8
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
expat (Alpine package) - update to 2.2.7-r0
expat (Red Hat package) - addressed in versions 2.1.0-12.el7, 2.2.5-4.el8
expat (Debian package) - update to 2.2.0-2+deb9u2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.3
IBM API Connect - update to 5.0.8.12
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
Tenable Nessus - update to 8.15.0
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
expat - addressed in versions 2.2.7-1.fc29, 2.2.7-1.fc30
Red Hat OpenShift Container Platform - update to 4.3.40
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
NetWorker Management Console - update to 19.12.0.1

External References

Related Security Bulletins