Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36641

Опубликовано: 05 янв. 2023
Источник: nvd
CVSS3: 5.5
CVSS3: 9.8
CVSS2: 4.9
EPSS Низкий

Описание

A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the file src/main/java/de/timroes/axmlrpc/ResponseParser.java. The manipulation leads to xml external entity reference. Upgrading to version 1.14.0 is able to address this issue. The patch is identified as 456752ebc1ef4c0db980cb5b01a0b3cd0a9e0bae. It is recommended to upgrade the affected component. VDB-217450 is the identifier assigned to this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gturri:axmlrpc:*:*:*:*:*:*:*:*
Версия до 1.12.1 (включая)

EPSS

Процентиль: 54%
0.00315
Низкий

5.5 Medium

CVSS3

9.8 Critical

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the file src/main/java/de/timroes/axmlrpc/ResponseParser.java. The manipulation leads to xml external entity reference. Upgrading to version 1.14.0 is able to address this issue. The patch is identified as 456752ebc1ef4c0db980cb5b01a0b3cd0a9e0bae. It is recommended to upgrade the affected component. VDB-217450 is the identifier assigned to this vulnerability.

CVSS3: 9.8
github
около 3 лет назад

aXMLRPC XML External Entity vulnerability

EPSS

Процентиль: 54%
0.00315
Низкий

5.5 Medium

CVSS3

9.8 Critical

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-611