Description
CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1470 | CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter. |
Github GHSA |
GHSA-m8gq-83gh-v42v | XML External Entities Vulnerability in CVRF-CSAF-Converter |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T05:25:31.128Z
Reserved: 2022-03-15T00:00:00.000Z
Link: CVE-2022-27193
No data.
Status : Modified
Published: 2022-03-15T05:15:07.193
Modified: 2024-11-21T06:55:22.957
Link: CVE-2022-27193
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA