Количество 2
Количество 2
CVE-2021-41042
больше 3 лет назад
In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
CVSS3: 5.3
EPSS: Низкий
GHSA-6296-mvgp-27hp
больше 3 лет назад
XML External Entity Reference in Eclipse Lyo
CVSS3: 4.2
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-41042 In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-6296-mvgp-27hp XML External Entity Reference in Eclipse Lyo | CVSS3: 4.2 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20