Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v723-58jv-2qc4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

Пакеты

Наименование

org.opensaml:opensaml

maven
Затронутые версииВерсия исправления

< 2.6.1

2.6.1

EPSS

Процентиль: 73%
0.0075
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

redhat
около 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

nvd
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

debian
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, ...

EPSS

Процентиль: 73%
0.0075
Низкий

Дефекты

CWE-200