Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjf8-hc3f-mpw4

Опубликовано: 30 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

EPSS

Процентиль: 100%
0.91576
Критический

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
redhat
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
nvd
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
debian
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML ...

CVSS3: 7.5
redos
больше 2 лет назад

Уязвимость pki-core

EPSS

Процентиль: 100%
0.91576
Критический

7.5 High

CVSS3

Дефекты

CWE-611