packetstormsecurity.com
http://packetstormsecurity.com/files/155619/Apache-Olingo-OData-4.6.x-XML-Injection.html CVE-2019-17554
MEDIUM
Improper Restriction of XML External Entity Reference in Apache Olingo
Record summary
CVE-2019-17554 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
OlingoBrowse Apache / Olingo | CVE List, VulnCheck | 4.0.0 to 4.6.0 | affected |
org.apache.olingo:odata-client-coreBrowse Maven / org.apache.olingo:odata-client-core | GitHub Advisory | 4.0.0 to < 4.7.0 · Fixed in 4.7.0 | affected |
org.apache.olingo:odata-server-coreBrowse Maven / org.apache.olingo:odata-server-core | GitHub Advisory | 4.0.0 to < 4.7.0 · Fixed in 4.7.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBApache Olingo OData 4.0 - XML External Entity InjectionExploitDB exploitby Compass SecurityNot analyzed1 file
References
9github.com
https://github.com/apache/olingo-odata4/commit/5948974ad28271818e2afe747c71cde56a7f2c63 github.com
https://github.com/apache/olingo-odata4/commit/c3f982db3d97e395d313ae8f231202bb2139882c issues.apache.org
https://issues.apache.org/jira/browse/OLINGO-1409 [announce] 20200131 Apache Software Foundation Security Report: 2019mailing list
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E [olingo-user] 20191204 [SECURITY] CVE-2019-17554: XML External Entity resolution attackmailing list
https://mail-archives.apache.org/mod_mbox/olingo-user/201912.mbox/%3CCAGSZ4d7Ty%3DL-n_iAzT6vcQp65BY29XZDS5tMoM8MdDrb1moM7A%40mail.gmail.com%3E nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17554 20191210 CVE-2019-17554 - Apache Olingo OData 4.0 - XML External Entity Resolution (XXE)mailing list
https://seclists.org/bugtraq/2019/Dec/11