Описание
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is e6fddca201790abab4f2c274341c0bb8835c3e73. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221480.
A flaw was found in java-xmlbuilder. The manipulation leads to an XML external entity (XXE) reference.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 3 | java-xmlbuilder | Not affected | ||
| Red Hat Fuse 7 | java-xmlbuilder | Not affected | ||
| Red Hat Integration Camel K 1 | java-xmlbuilder | Not affected | ||
| Red Hat JBoss Data Grid 7 | java-xmlbuilder | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | java-xmlbuilder | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | java-xmlbuilder | Not affected | ||
| Red Hat JBoss Fuse 6 | java-xmlbuilder | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | java-xmlbuilder | Out of support scope |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is e6fddca201790abab4f2c274341c0bb8835c3e73. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221480.
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is e6fddca201790abab4f2c274341c0bb8835c3e73. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221480.
java-xmlbuilder vulnerable to XML External Entity Reference
9.8 Critical
CVSS3