CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
Percentile
61.3%
JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability
in MsBibImporter XML Parser that can result in disclosure of confidential
data, denial of service, server side request forgery, port scanning. This
attack appear to be exploitable via Specially crafted MsBib file. This
vulnerability appears to have been fixed in after commit 89f855d.
0dd.zone/2018/08/08/JabRef-XXE/
github.com/JabRef/jabref/commit/89f855d76713b4cd25ac0830c719cd61c511851e
github.com/JabRef/jabref/issues/4229
launchpad.net/bugs/cve/CVE-2018-1000652
nvd.nist.gov/vuln/detail/CVE-2018-1000652
security-tracker.debian.org/tracker/CVE-2018-1000652
www.cve.org/CVERecord?id=CVE-2018-1000652
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
Percentile
61.3%