Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c9q-qwrc-f486

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

XML External Entity Reference in org.picketlink:picketlink-common

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.

Пакеты

Наименование

org.picketlink:picketlink-common

maven
Затронутые версииВерсия исправления

< 2.7.0.Final

2.7.0.Final

EPSS

Процентиль: 85%
0.02552
Низкий

Дефекты

CWE-611

Связанные уязвимости

redhat
больше 11 лет назад

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.

nvd
больше 11 лет назад

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.

EPSS

Процентиль: 85%
0.02552
Низкий

Дефекты

CWE-611