VDB
BDU%3A2025-11250
BDU%3A2025-11250
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость методов addElement и addAttribute библиотеки для работы с XML, XPath и XSLT dom4j, позволяющая нарушителю проводить XXE-атаки
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc., Google Inc | Ubuntu, Suse Linux Enterprise Server, SUSE Linux Enterprise Software Development Kit, OpenSUSE Leap, SUSE Linux Enterprise Server for SAP Applications, openSUSE Tumbleweed, SUSE Manager Server, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Development Tools, dom4j, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Manager Proxy, SUSE Enterprise Storage, SUSE Linux Enterprise High Performance Computing, SUSE Package Hub, Red Hat Fuse, Red Hat JBoss Enterprise Application Platform, Android Studio |
Timeline
- Sep 17, 2025 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://access.redhat.com/security/cve/cve-2018-1000632 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://security-tracker.debian.org/tracker/CVE-2018-1000632 advisory
- https://ubuntu.com/security/CVE-2018-1000632 advisory
- https://github.com/dom4j/dom4j/commit/e598eb43d418744c4dbf62f647dd2381c9ce9387 url
- https://www.suse.com/security/cve/CVE-2018-1000632.html advisory