Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23901

Опубликовано: 25 янв. 2021
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Nutch 1.18.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:nutch:*:*:*:*:*:*:*:*
Версия до 1.18 (исключая)
Конфигурация 2
cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01068
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 9.1
github
почти 4 года назад

XML external entity (XXE) injection in Apache Nutch

EPSS

Процентиль: 77%
0.01068
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611