Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwwr-fjgh-cv2x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Restriction of XML External Entity Reference in Castor

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

Пакеты

Наименование

org.codehaus.castor:castor

maven
Затронутые версииВерсия исправления

< 1.3.3

1.3.3

Наименование

castor:castor

maven
Затронутые версииВерсия исправления

<= 1.0

Отсутствует

EPSS

Процентиль: 94%
0.07794
Низкий

Дефекты

CWE-611

Связанные уязвимости

ubuntu
около 12 лет назад

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

redhat
около 12 лет назад

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

nvd
около 12 лет назад

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

EPSS

Процентиль: 94%
0.07794
Низкий

Дефекты

CWE-611