Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-2414

Опубликовано: 29 июл. 2022
Источник: debian
EPSS Критический

Описание

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dogtag-pkifixed11.0.6-1package
dogtag-pkino-dsabullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2104676

  • https://github.com/dogtagpki/pki/pull/4021

  • https://github.com/dogtagpki/pki/commit/4e893243d72ad766558c10c907841f5f9c047055

EPSS

Процентиль: 100%
0.91576
Критический

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
redhat
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
nvd
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
redos
больше 2 лет назад

Уязвимость pki-core

rocky
почти 3 года назад

Important: pki-core:10.6 and pki-deps:10.6 security and bug fix update

EPSS

Процентиль: 100%
0.91576
Критический