CVE-2018-1000844 is a critical XML External Entity (XXE) vulnerability affecting Square Open Source Retrofit versions prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437. This flaw, rated 9.1 CRITICAL (CVSSv3), allows an unauthenticated attacker to remotely read arbitrary files from the filesystem or perform Server-Side Request Forgery (SSRF) attacks without user interaction. While the vulnerability has a high FAUCET Risk Score of 73/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The issue has been patched in later versions of Retrofit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, < 2.5.0CPE matchmatch criteria | cpe:2.3:a:squareup:retrofit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.