CVE-2018-20000: Improper Restriction of XML External Entity Reference
(updated )
Apereo Bedework bw-webdav allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java
and webdav/servlet/common/PostRequestPars.java
.
References
Detect and mitigate CVE-2018-20000 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →