[MAVEN:GHSA-XMVG-W4F9-99R7] XML External Entity (XXE) vulnerability in bw-calendar-engine

Severity Critical
Affected Packages 1
CVEs 1

bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.

Package Affected Version
pkg:maven/org.bedework.caleng/bw-calendar-engine <= 3.12.2
ID
MAVEN:GHSA-XMVG-W4F9-99R7
Severity
critical
URL
https://github.com/advisories/GHSA-xmvg-w4f9-99r7
Published
2018-12-20T22:02:51
(5 years ago)
Modified
2023-01-09T05:04:06
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bedework.caleng/bw-calendar-engine org.bedework.caleng bw-calendar-engine <= 3.12.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...