Описание
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
EPSS
Процентиль: 24%
0.00083
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-134
Связанные уязвимости
CVSS3: 5.5
github
12 месяцев назад
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
EPSS
Процентиль: 24%
0.00083
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-134