Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6440

Опубликовано: 14 фев. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

РелизСтатусПримечание
artful

not-affected

uses C implementation
devel

not-affected

uses C implementation
esm-apps/xenial

not-affected

uses C implementation
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses C implementation]]
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was not-affected (uses C implementation
quantal

ignored

end of life
raring

ignored

end of life
saucy

ignored

end of life

Показывать по

EPSS

Процентиль: 73%
0.0075
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

nvd
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

debian
почти 12 лет назад

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, ...

github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

EPSS

Процентиль: 73%
0.0075
Низкий

5 Medium

CVSS2