← Vulnerability feed

Vulnerability record · CVE-2018-17198 · published 28 May 2019

CVE-2018-17198: Apache roller server-side request forgery (ssrf) vulnerability

Apache · Roller

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. Note that this vulnerability exists even if Roller XML-RPC interface is disable via the Roller web admin UI. Mitigation: There are a couple of ways you can fix this vulnerability: 1) Upgrade to the latest version of Roller, which is now 5.2.2 2) Or, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping as shown below: <!-- <servlet-mapping> <servlet-name>XmlRpcServlet</servlet-name> <url-pattern>/roller-services/xmlrpc</url-pattern> </servlet-mapping> -->

9.8 CVSS 3.0 Critical EPSS 4.1% · top 9.5% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.0 base score, v2 7.5
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. Note that this vulnerability exists even if Roller XML-RPC interface is disable via the Roller web admin UI. Mitigation: There are a couple of ways you can fix this vulnerability: 1) Upgrade to the latest version of Roller, which is now 5.2.2 2) Or, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping as shown below: <!-- <servlet-mapping> <servlet-name>XmlRpcServlet</servlet-name> <url-pattern>/roller-services/xmlrpc</url-pattern> </servlet-mapping> -->

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-17198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0030Apache roller xml external entity (xxe) vulnerabilityThe XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.EPSS 17%7.5CVE-2021-33580Apache roller uncontrolled resource consumption vulnerabilityUser controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…EPSS 3.3%7.2CVE-2015-0249Apache roller code injection vulnerabilityThe weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…EPSS 4.6%6.8CVE-2013-4212Apache Roller OGNL injection in ActionSupport getText methodsApache Roller before 5.0.2 passes attacker-controlled parameters into OGNL expressions inside certain getText methods of the ActionSupport controller…EPSS 81%analysed6.8CVE-2012-2380Apache roller cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…EPSS 1.6%6.1CVE-2019-0234Apache roller cross-site scripting vulnerabilityA Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…EPSS 3.4%5.4CVE-2024-25090Apache roller improper input validation vulnerabilityInsufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …EPSS 0.75%5.4CVE-2023-37581Apache roller cross-site scripting vulnerabilityInsufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-17198), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.