Vulnerabilities > CVE-2017-18197 - XXE vulnerability in Jgraph Mxgraph
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Debian Local Security Checks NASL id DEBIAN_DLA-1299.NASL description It was discovered that there was a potential XML External Entity (XXE) attack in libjgraphx-java, a diagramming library for Java applications. For Debian 7 last seen 2020-03-17 modified 2018-03-05 plugin id 107118 published 2018-03-05 reporter This script is Copyright (C) 2018-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/107118 title Debian DLA-1299-1 : libjgraphx-java security update NASL family Fedora Local Security Checks NASL id FEDORA_2018-B3F8BEE2E0.NASL description Security fix for CVE-2017-18197 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2018-04-23 plugin id 109225 published 2018-04-23 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109225 title Fedora 26 : jgraphx (2018-b3f8bee2e0) NASL family SuSE Local Security Checks NASL id OPENSUSE-2018-228.NASL description This update for jgraphx fixes the following issues : Security issue fixed : - CVE-2017-18197: Fixed missing flags in SAXParserFactory instance in convert() to prevent XML External Entity (XXE) attacks (boo#1083413). last seen 2020-06-05 modified 2018-03-07 plugin id 107183 published 2018-03-07 reporter This script is Copyright (C) 2018-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/107183 title openSUSE Security Update : jgraphx (openSUSE-2018-228) NASL family Fedora Local Security Checks NASL id FEDORA_2018-B268B5BBB5.NASL description Security fix for CVE-2017-18197 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2018-04-23 plugin id 109224 published 2018-04-23 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109224 title Fedora 27 : jgraphx (2018-b268b5bbb5)