Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-2414

Опубликовано: 29 июл. 2022
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS3: 7.5

Описание

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

DNE

esm-apps/bionic

ignored

risks regressions
esm-apps/focal

ignored

risks regressions
esm-apps/jammy

released

11.0.0-1ubuntu0.1~esm1
esm-apps/xenial

ignored

risks regressions
focal

ignored

end of standard support, was needed
impish

ignored

end of life, was needed
jammy

needed

kinetic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 100%
0.91576
Критический

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
nvd
почти 3 года назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
debian
почти 3 года назад

Access to external entities when parsing XML documents can lead to XML ...

CVSS3: 7.5
redos
около 2 лет назад

Уязвимость pki-core

rocky
больше 2 лет назад

Important: pki-core:10.6 and pki-deps:10.6 security and bug fix update

EPSS

Процентиль: 100%
0.91576
Критический

7.5 High

CVSS3