Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw3r-pfmg-xp92

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Improper Restriction of Recursive Entity References in Apache XMLBeans

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Пакеты

Наименование

org.apache.xmlbeans:xmlbeans

maven
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 55%
0.00322
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-776

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 7.4
redhat
около 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 9.1
nvd
около 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVSS3: 9.1
debian
около 5 лет назад

The XML parsers used by XMLBeans up to version 2.6.0 did not set the p ...

suse-cvrf
больше 3 лет назад

Security update for xmlbeans

EPSS

Процентиль: 55%
0.00322
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-776