Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0217

Опубликовано: 26 авг. 2022
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*
Версия до 0.11.12 (исключая)

EPSS

Процентиль: 63%
0.00456
Низкий

7.5 High

CVSS3

Дефекты

CWE-776
CWE-611

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

CVSS3: 7.5
debian
больше 3 лет назад

It was discovered that an internal Prosody library to load XML based o ...

suse-cvrf
около 4 лет назад

Security update for prosody

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость реализации модуля WebSocket сервера для Jabber/XMPP Prosody, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 63%
0.00456
Низкий

7.5 High

CVSS3

Дефекты

CWE-776
CWE-611