VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 13 of 67
  • CVE-2021-3902CriNov 15, 2024
    risk 0.57cvss 9.8epss 0.01

    An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the…

  • CVE-2024-51132CriNov 5, 2024
    risk 0.57cvss 9.8epss 0.02

    An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

  • CVE-2024-21255HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2023-37233HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

  • CVE-2024-22218HigAug 15, 2024
    risk 0.57cvss 8.8epss 0.01

    XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code…

  • CVE-2023-46502CriOct 30, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.

  • CVE-2023-36419HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability

  • CVE-2023-20855HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.01

    VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information…

  • CVE-2023-24323HigFeb 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.

  • CVE-2023-24443CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-24441CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-24430CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-24429CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file…

  • CVE-2022-47514HigDec 18, 2022
    risk 0.57cvss 8.8epss 0.01

    An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.

  • CVE-2022-25628HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

  • CVE-2022-46682CriDec 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45397CriNov 15, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-43570HigNov 4, 2022
    risk 0.57cvss 8.8epss 0.01

    In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

  • CVE-2022-41226CriSep 21, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-34793HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.