Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3709

Опубликовано: 11 авг. 2016
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

A Cross-site scripting (XSS) vulnerability was found in libxml2. A specially crafted input, when serialized and re-parsed by the libxml2 library, will result in a document with element attributes that did not exist in the original document.

Отчет

Red Hat JBoss Core Services already included the flaw fixes when the CVE was published over the version of httpd 2.4.51.SP1 GA.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 9libxml2Not affected
Red Hat JBoss Core Serviceslibxml2Not affected
Red Hat Enterprise Linux 8libxml2FixedRHSA-2022:771508.11.2022
Red Hat Enterprise Linux 8libxml2FixedRHSA-2022:771508.11.2022
Red Hat Enterprise Linux 8.6 Extended Update Supportlibxml2FixedRHSA-2023:476728.08.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2112766libxml2: Incorrect server side include parsing can lead to XSS

EPSS

Процентиль: 28%
0.00098
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

CVSS3: 6.1
nvd
почти 3 года назад

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

CVSS3: 6.1
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.1
debian
почти 3 года назад

Possible cross-site scripting vulnerability in libxml after commit 960 ...

rocky
больше 2 лет назад

Moderate: libxml2 security update

EPSS

Процентиль: 28%
0.00098
Низкий

6.1 Medium

CVSS3