No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22312 | An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side request forgery (SSRF). The issue was addressed by disabling external entity processing for the affected XML parser in versions SE.2025.1 and 2025.1.2. |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ETQ Reliance CG XML External Entity (XXE) Injection in SSO SAML Handler | ETQ Reliance CG < SE.2025.1 / < 2025.1.2 XXE Injection in SSO SAML Handler |
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side request forgery (SSRF). The issue was addressed by disabling external entity processing for the affected XML parser in versions SE.2025.1 and 2025.1.2. | |
| Title | ETQ Reliance CG XML External Entity (XXE) Injection in SSO SAML Handler | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-04T22:24:04.974Z
Reserved: 2025-04-15T19:15:22.563Z
Link: CVE-2025-34142
Updated: 2025-07-22T13:29:01.298Z
Status : Awaiting Analysis
Published: 2025-07-22T13:15:24.970
Modified: 2025-11-04T23:15:35.573
Link: CVE-2025-34142
No data.
OpenCVE Enrichment
No data.
EUVD