Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv32-7r6p-xhhh

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Moderate severity vulnerability that affects com.adobe.xmp:xmpcore

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Пакеты

Наименование

com.adobe.xmp:xmpcore

maven
Затронутые версииВерсия исправления

< 5.1.3

5.1.3

EPSS

Процентиль: 71%
0.00682
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 7.5
redhat
больше 9 лет назад

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 7.5
nvd
больше 9 лет назад

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS

Процентиль: 71%
0.00682
Низкий

7.5 High

CVSS3

Дефекты

CWE-611