Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw3r-pfmg-xp92

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Improper Restriction of Recursive Entity References in Apache XMLBeans

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Пакеты

Наименование

org.apache.xmlbeans:xmlbeans

maven
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 93%
0.06215
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-776

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 7.4
redhat
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 9.1
nvd
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 9.1
debian
больше 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the p ...

suse-cvrf
почти 4 года назад

Security update for xmlbeans

EPSS

Процентиль: 93%
0.06215
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-776