Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw5h-cmh3-8j6j

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

EPSS

Процентиль: 33%
0.00417
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
redhat
9 дней назад

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CVSS3: 9.8
nvd
9 дней назад

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

EPSS

Процентиль: 33%
0.00417
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611