CVE-2019-9628
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- xmltooling project/xmltooling · canonical/ubuntu linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.htmlMailing List, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190611-0003/Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20190311.txtThird Party Advisory
- https://usn.ubuntu.com/3921-1/Third Party Advisory
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisoriesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00095.htmlMailing List, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1819912Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190611-0003/Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20190311.txtThird Party Advisory
- https://usn.ubuntu.com/3921-1/Third Party Advisory
- https://wiki.shibboleth.net/confluence/display/SP3/SecurityAdvisoriesThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.