Security Advisory

CVE-2018-10868

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-26 18:03:25
Last updated 2024-08-05 07:46:47
Assigner redhat
State PUBLISHED

Description

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.