Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32754

Опубликовано: 12 июл. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 3.5
EPSS Низкий

Описание

FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from external locations. In order for this to occur, the XML-based format for sources and sinks had to be used and the attacker had to able control the source/sink definition file. The vulnerability was patched in version 2.9.0. As a workaround, do not allow untrusted entities to control the source/sink definition file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flowdroid_project:flowdroid:*:*:*:*:*:*:*:*
Версия до 2.9.0 (исключая)

EPSS

Процентиль: 53%
0.00305
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-611
CWE-611

EPSS

Процентиль: 53%
0.00305
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-611
CWE-611