CVE-2016-5002: Improper Restriction of XML External Entity Reference
(updated )
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
References
- www.openwall.com/lists/oss-security/2016/07/12/5
- access.redhat.com/errata/RHSA-2018:3768
- exchange.xforce.ibmcloud.com/vulnerabilities/115042
- github.com/advisories/GHSA-wp35-6jqv-r33m
- nvd.nist.gov/vuln/detail/CVE-2016-5002
- web.archive.org/web/20210123151805/http://www.securityfocus.com/bid/91736
- web.archive.org/web/20211021044107/http://www.securitytracker.com/id/1036294
- web.archive.org/web/20230520164025/https://0ang3el.blogspot.com/2016/07/beware-of-ws-xmlrpc-library-in-your.html
Detect and mitigate CVE-2016-5002 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →