Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r89j-vhg3-xw33

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

EPSS

Процентиль: 64%
0.01155
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

redhat
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS3: 5.5
nvd
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS3: 5.5
debian
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users ...

EPSS

Процентиль: 64%
0.01155
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611