XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java.

Project Subscriptions

Vendors Products
Eclipse Subscribe
Wild Web Developer Subscribe
Theia Xml Extension Project Subscribe
Theia Xml Extension Subscribe
Xml Language Server Project Subscribe
Xml Server Project Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8013 XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:47:14.103Z

Reserved: 2019-10-19T00:00:00.000Z

Link: CVE-2019-18213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-23T22:15:10.943

Modified: 2024-11-21T04:32:50.700

Link: CVE-2019-18213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses