CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 15 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10799 | Cri | 0.57 | 9.8 | 0.02 | Mar 20, 2020 | The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. | ||
| CVE-2013-4334 | Cri | 0.57 | 9.8 | 0.01 | Feb 7, 2020 | opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities | ||
| CVE-2019-15637 | Hig | 0.57 | 8.1 | 0.14 | Aug 26, 2019 | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop. | ||
| CVE-2015-3907 | Cri | 0.57 | 9.8 | 0.02 | Jul 3, 2019 | CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks. | ||
| CVE-2017-18111 | Hig | 0.57 | 8.7 | 0.02 | Mar 29, 2019 | The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth… | ||
| CVE-2019-3772 | Cri | 0.57 | 9.8 | 0.03 | Jan 18, 2019 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | ||
| CVE-2018-16166 | Hig | 0.57 | 8.8 | 0.02 | Jan 9, 2019 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | ||
| CVE-2018-11788 | Cri | 0.57 | 9.8 | 0.07 | Jan 7, 2019 | Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against… | ||
| CVE-2019-5312 | Cri | 0.57 | 9.8 | 0.02 | Jan 4, 2019 | An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318. | ||
| CVE-2018-14720 | Cri | 0.57 | 9.8 | 0.08 | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | ||
| CVE-2018-1000889 | Hig | 0.57 | 8.8 | 0.01 | Dec 28, 2018 | Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration.… | ||
| CVE-2018-20433 | Cri | 0.57 | 9.8 | 0.05 | Dec 24, 2018 | c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. | ||
| CVE-2018-20059 | Cri | 0.57 | 9.8 | 0.01 | Dec 11, 2018 | jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE. | ||
| CVE-2018-12544 | Cri | 0.57 | 9.8 | 0.02 | Oct 10, 2018 | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a… | ||
| CVE-2018-10614 | Hig | 0.57 | 8.8 | 0.01 | Oct 9, 2018 | An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files. | ||
| CVE-2018-12243 | Hig | 0.57 | 8.8 | 0.01 | Sep 19, 2018 | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI… | ||
| CVE-2018-8027 | Cri | 0.57 | 9.8 | 0.06 | Jul 31, 2018 | Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. | ||
| CVE-2017-7464 | Hig | 0.57 | 8.7 | 0.02 | Jul 27, 2018 | It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing. | ||
| CVE-2014-2296 | Hig | 0.57 | 8.8 | 0.02 | Jul 20, 2018 | XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data. | ||
| CVE-2018-14065 | Cri | 0.57 | 9.8 | 0.02 | Jul 15, 2018 | XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. |
- risk 0.57cvss 9.8epss 0.02
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
- risk 0.57cvss 9.8epss 0.01
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
- risk 0.57cvss 8.1epss 0.14
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
- risk 0.57cvss 9.8epss 0.02
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
- risk 0.57cvss 8.7epss 0.02
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth…
- risk 0.57cvss 9.8epss 0.03
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
- risk 0.57cvss 8.8epss 0.02
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
- risk 0.57cvss 9.8epss 0.07
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against…
- risk 0.57cvss 9.8epss 0.02
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
- risk 0.57cvss 9.8epss 0.08
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- risk 0.57cvss 8.8epss 0.01
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration.…
- risk 0.57cvss 9.8epss 0.05
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
- risk 0.57cvss 9.8epss 0.01
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
- risk 0.57cvss 9.8epss 0.02
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a…
- risk 0.57cvss 8.8epss 0.01
An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.
- risk 0.57cvss 8.8epss 0.01
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI…
- risk 0.57cvss 9.8epss 0.06
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
- risk 0.57cvss 8.7epss 0.02
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
- risk 0.57cvss 8.8epss 0.02
XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data.
- risk 0.57cvss 9.8epss 0.02
XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.