Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23926

Опубликовано: 14 янв. 2021
Источник: debian

Описание

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xmlbeansfixed3.0.2-1package

Примечания

  • https://issues.apache.org/jira/browse/XMLBEANS-517

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 7.4
redhat
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 9.1
nvd
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

suse-cvrf
почти 4 года назад

Security update for xmlbeans

suse-cvrf
почти 4 года назад

Security update for xmlbeans