Back

HIGH

juddi-client: XML Entity Expansion in WADL2Java or WSDL2Java classes

Published Feb 9, 2018

Description

In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.

Affected products

Remediation

Red Hat statement

No Red Hat products are affected by CVE-2018-1307.

Metrics

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Feb 9, 2018
Updated Sep 16, 2024
Reserved Dec 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 10, 2017
GHSA-P99P-726H-C8V5