Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c2p-rqx3-w4px

Опубликовано: 23 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
ubuntu
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
redhat
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
nvd
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 9.1
debian
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.1 ...

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611