CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 13 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3902 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2024 | An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the… | ||
| CVE-2024-51132 | Cri | 0.57 | 9.8 | 0.02 | Nov 5, 2024 | An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | ||
| CVE-2024-21255 | Hig | 0.57 | 8.8 | 0.01 | Oct 15, 2024 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | ||
| CVE-2023-37233 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2024 | Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. | ||
| CVE-2024-22218 | Hig | 0.57 | 8.8 | 0.01 | Aug 15, 2024 | XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code… | ||
| CVE-2023-46502 | Cri | 0.57 | 9.8 | 0.01 | Oct 30, 2023 | An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory. | ||
| CVE-2023-36419 | Hig | 0.57 | 8.8 | 0.02 | Oct 10, 2023 | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | ||
| CVE-2023-20855 | Hig | 0.57 | 8.8 | 0.01 | Feb 22, 2023 | VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information… | ||
| CVE-2023-24323 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2023 | Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. | ||
| CVE-2023-24443 | Cri | 0.57 | 9.8 | 0.01 | Jan 26, 2023 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2023-24441 | Cri | 0.57 | 9.8 | 0.01 | Jan 26, 2023 | Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2023-24430 | Cri | 0.57 | 9.8 | 0.01 | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2023-24429 | Cri | 0.57 | 9.8 | 0.01 | Jan 26, 2023 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file… | ||
| CVE-2022-47514 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2022 | An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request. | ||
| CVE-2022-25628 | Hig | 0.57 | 8.8 | 0.01 | Dec 16, 2022 | An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | ||
| CVE-2022-46682 | Cri | 0.57 | 9.8 | 0.01 | Dec 12, 2022 | Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45397 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-43570 | Hig | 0.57 | 8.8 | 0.01 | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error. | ||
| CVE-2022-41226 | Cri | 0.57 | 9.8 | 0.01 | Sep 21, 2022 | Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-34793 | Hig | 0.57 | 8.8 | 0.01 | Jun 30, 2022 | Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
- risk 0.57cvss 9.8epss 0.01
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the…
- risk 0.57cvss 9.8epss 0.02
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
- risk 0.57cvss 8.8epss 0.01
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
- risk 0.57cvss 8.8epss 0.00
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
- risk 0.57cvss 8.8epss 0.01
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code…
- risk 0.57cvss 9.8epss 0.01
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
- risk 0.57cvss 8.8epss 0.02
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information…
- risk 0.57cvss 8.8epss 0.01
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
- risk 0.57cvss 9.8epss 0.01
Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 9.8epss 0.01
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 9.8epss 0.01
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 9.8epss 0.01
Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file…
- risk 0.57cvss 8.8epss 0.01
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
- risk 0.57cvss 8.8epss 0.01
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
- risk 0.57cvss 9.8epss 0.01
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 9.8epss 0.01
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 8.8epss 0.01
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
- risk 0.57cvss 9.8epss 0.01
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 8.8epss 0.01
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.