← Vulnerability feed

Vulnerability record · CVE-2018-11788 · published 7 January 2019

CVE-2018-11788: Apache karaf xml external entity (xxe) vulnerability

Apache · Karaf

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

9.8 CVSS 3.0 Critical EPSS 7.3% · top 5.8% CWE-611 · XML external entity (XXE)
9.8CVSS 3.0 base score, v2 7.5
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11788 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-40145Apache karaf improper input validation vulnerabilityThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function j…EPSS 2.4%8.8CVE-2018-11786Apache karaf improper privilege management vulnerabilityIn Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…EPSS 1.9%8.1CVE-2021-41766Apache karaf deserialization of untrusted data vulnerabilityApache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…EPSS 2.0%8.1CVE-2020-28052Bouncycastle bc-java vulnerabilityAn issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data …EPSS 7.2%8.1CVE-2018-11787Apache karaf improper authentication vulnerabilityIn Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…EPSS 2.6%6.5CVE-2019-0191Apache karaf path traversal vulnerabilityApache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …EPSS 4.9%6.5CVE-2016-8750Apache karaf ldap injection vulnerabilityApache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a…EPSS 5.2%6.3CVE-2020-11980Apache karaf server-side request forgery (ssrf) vulnerabilityIn Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2018-11788), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.