karaf: XML external entity processing
Published Jan 7, 2019
9.8
CRITICALCVSS 3.0
EPSS 7.35%
Description
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
Affected products
-
- Version Any Apache Karaf version prior to 4.1.7 and 4.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Karaf | n/a |
|
No data.
Red Hat Fuse 7
karaf
Affected
Red Hat JBoss A-MQ 6
karaf
Will not fix
Red Hat JBoss Fuse 6
karaf
Will not fix
Red Hat JBoss Fuse Service Works 6
karaf
Will not fix
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
opendaylight
Out of support scope
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Out of support scope
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | karaf | Affected | n/a |
| Red Hat JBoss A-MQ 6 | karaf | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | karaf | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | karaf | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | opendaylight | Out of support scope | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Out of support scope | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform: Karaf is used by RHOSP's OpenDaylight, and this flaw impacts the loading of XML documents within Karaf, allowing arbitrary XML to be injected into parsed documents. The impact of this vulnerability is reduced in OpenDaylight, given karaf is an administrative component and not normally exposed to public networks or non-privileged users, and therefore will not be fixed at this time. Fuse 7: The impact of this vulnerability is reduced, as exploiting it would require a authenticated user, and no unsecured endpoints are exposed to the network
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 7.35% (0.07349) | 94.22th | v5 (v2026.06.15) |
| Aug 23, 2026 | 6.37% (0.06374) | 93.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.48% (0.07480) | 93.67th | v5 (v2026.06.15) |
| Mar 30, 2025 | 24.75% (0.24747) | 95.68th | v4 (v2025.03.14) |
| Mar 29, 2025 | 54.25% (0.54250) | 97.12th | v4 (v2025.03.14) |
| Mar 28, 2025 | 24.75% (0.24747) | 95.68th | v4 (v2025.03.14) |
| Mar 27, 2025 | 54.25% (0.54250) | 97.68th | v4 (v2025.03.14) |
| Mar 24, 2025 | 35.95% (0.35947) | 96.75th | v4 (v2025.03.14) |
| Mar 20, 2025 | 54.25% (0.54250) | 97.83th | v4 (v2025.03.14) |
| Mar 19, 2025 | 64.91% (0.64912) | 98.29th | v4 (v2025.03.14) |
| Mar 17, 2025 | 54.25% (0.54250) | 97.76th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00100) | 42.96th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.10% (0.00100) | 41.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00100) | 39.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.03% (0.09029) | 94.14th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.82% (0.07819) | 84.70th | v5 (v2026.06.15) |
| Apr 14, 2021 | 7.82% (0.07819) | 0.00th | v1 |
References (9)
- http://karaf.apache.org/security/cve-2018-11788.txt x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/bid/106479 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-11788 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1663857 Issue Tracking
- https://github.com/advisories/GHSA-92wj-x78c-m4fx Advisory
- https://github.com/apache/karaf/commit/0c36c50bc158739c8fc8543122a6740c54adafca
- https://nvd.nist.gov/vuln/detail/CVE-2018-11788
- https://web.archive.org/web/20200227101219/https://www.securityfocus.com/bid/106479/
- https://www.cve.org/CVERecord?id=CVE-2018-11788
| Link | Providers | Tags |
|---|---|---|
| http://karaf.apache.org/security/cve-2018-11788.txt | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/bid/106479 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-11788 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1663857 | Issue Tracking | |
| https://github.com/advisories/GHSA-92wj-x78c-m4fx | Advisory | |
| https://github.com/apache/karaf/commit/0c36c50bc158739c8fc8543122a6740c54adafca | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-11788 | ||
| https://web.archive.org/web/20200227101219/https://www.securityfocus.com/bid/106479/ | ||
| https://www.cve.org/CVERecord?id=CVE-2018-11788 |
Change history (0)
No recorded changes yet.