Vulnerabilities > Apache > Roller > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-05-28 | CVE-2018-17198 | Server-Side Request Forgery (SSRF) vulnerability in Apache Roller Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. | 9.8 |
2017-10-10 | CVE-2014-0030 | XXE vulnerability in Apache Roller The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | 9.8 |