[MAVEN:GHSA-JXM5-5XCW-H57Q] exist-db:exist-core XML External Entity (XXE) vulnerability

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Package Affected Version
pkg:maven/org.exist-db/exist-core < 5.1.0
Package Fixed Version
pkg:maven/org.exist-db/exist-core = 5.1.0
ID
MAVEN:GHSA-JXM5-5XCW-H57Q
Severity
critical
URL
https://github.com/advisories/GHSA-jxm5-5xcw-h57q
Published
2018-12-20T22:02:17
(5 years ago)
Modified
2023-01-11T05:06:20
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.exist-db/exist-core org.exist-db exist-core < 5.1.0
Fixed pkg:maven/org.exist-db/exist-core org.exist-db exist-core = 5.1.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...