High severity7.5NVD Advisory· Published Sep 11, 2020· Updated Jun 17, 2026
CVE-2020-11991
CVE-2020-11991
Description
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
Affected products
2Patches
Vulnerability mechanics
References
1- lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache.org%3EnvdExploitMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.