Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38555

Опубликовано: 11 сент. 2021
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:any23:*:*:*:*:*:*:*:*
Версия до 2.5 (исключая)

EPSS

Процентиль: 79%
0.01272
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
github
больше 4 лет назад

XML Injection in Any23

EPSS

Процентиль: 79%
0.01272
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611