Описание
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Software Collections | rh-thermostat16-jgraphx | Will not fix |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1550353jgraphx: XML External Entity (XXE) vulnerability in mxGraphViewImageReader.java:convert()
EPSS
Процентиль: 63%
0.0044
Низкий
4.8 Medium
CVSS3
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 8 лет назад
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
CVSS3: 9.8
nvd
почти 8 лет назад
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
CVSS3: 9.8
debian
почти 8 лет назад
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserF ...
EPSS
Процентиль: 63%
0.0044
Низкий
4.8 Medium
CVSS3