DoS Vulnerability in Apache PDFBox (CVE-2018-11797)
Issue date: 04-12-2018Affects versions: 12.6, 12.5, 11.2, 10.2
Issue ID: SECURITY-83
Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.6.0, 12.5.1, 11.2.10, 10.2.14 and earlier versions.
Severity
Medium
Description
A carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
See: CVE-2018-11797
This vulnerability is classified with severity medium, and may (also) apply to project specific usages of the Apache PDFBox library within a Hippo CMS project.
The Apache PDFBox version in all supported CMS maintenance versions 12.6.0, 12.5.1, 11.2.10, and 10.2.14 has been updated to version 1.8.16 or 2.0.12.
Instructions
Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.