Логотип exploitDog
bind:CVE-2022-39135
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39135

Количество 4

Количество 4

redhat логотип

CVE-2022-39135

больше 3 лет назад

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-39135

больше 3 лет назад

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fj2m-w3wv-x9pr

больше 3 лет назад

Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2022-07189

больше 3 лет назад

Уязвимость фреймворка управления динамическими данными Apache Calcite, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю проводить XXE-атаки

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fj2m-w3wv-x9pr

Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-07189

Уязвимость фреймворка управления динамическими данными Apache Calcite, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю проводить XXE-атаки

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу