Описание
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
EPSS
Процентиль: 33%
0.0013
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 5.3
github
около 1 года назад
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
EPSS
Процентиль: 33%
0.0013
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-611