5
CVSSv2

CVE-2018-10868

Published: 26/05/2021 Updated: 10/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat certification 7.0

Vendor Advisories

Impact: Moderate Public Date: 2018-06-21 CWE: CWE-776 Bugzilla: 1593776: CVE-2018-10868 redhat-certific ...