Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j6p-6hm2-m4qc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

EPSS

Процентиль: 59%
0.00376
Низкий

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.3
redhat
почти 5 лет назад

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

CVSS3: 7.5
nvd
больше 4 лет назад

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

EPSS

Процентиль: 59%
0.00376
Низкий

Дефекты

CWE-611