CVE-2018-12544
Moderate severity vulnerability that affects io.vertx:vertx-core
EPSS 0.59%
Description
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.
How to fix CVE-2018-12544
To remediate CVE-2018-12544, upgrade the affected package to a fixed version below.
- Maven/io.vertx:vertx-core—upgrade to 3.5.4 or later
Is CVE-2018-12544 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.5.0, < 3.5.4