Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8010

Опубликовано: 16 апр. 2026
Источник: nvd
CVSS3: 3.5
CVSS3: 7.5
EPSS Низкий

Описание

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references.

By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.0.397 (исключая)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 3.2.1 (включая) до 3.2.1.27 (исключая)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.0.310 (включая)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.0.171 (исключая)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.0.127 (исключая)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Версия от 4.3.0 (включая) до 4.3.0.39 (исключая)

EPSS

Процентиль: 20%
0.00273
Низкий

3.5 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 3.5
github
5 месяцев назад

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.

EPSS

Процентиль: 20%
0.00273
Низкий

3.5 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-611