CVE-2018-1000838

Source
https://cve.org/CVERecord?id=CVE-2018-1000838
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000838.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000838
Published
2018-12-20T15:29:01.767Z
Modified
2026-04-10T04:44:31.610241Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

References

Affected packages

Git / github.com/sleuthkit/autopsy

Affected ranges

Type
GIT
Repo
https://github.com/sleuthkit/autopsy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.9.0"
        }
    ]
}

Affected versions

Other
VisualStudio_2010
autopsy-3.*
autopsy-3.0.0
autopsy-3.0.0b3
autopsy-3.0.0b4
autopsy-3.0.0b5
autopsy-3.0.2
autopsy-3.0.3
autopsy-3.0.4
autopsy-3.0.6
autopsy-3.0.7
autopsy-3.1.0beta1
autopsy-4.*
autopsy-4.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000838.json"