CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,372)
page 44 of 69| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5625 | Med | 0.42 | 6.5 | 0.00 | Jul 18, 2024 | Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1. | ||
| CVE-2024-38374 | Hig | 0.42 | 7.5 | 0.01 | Jun 28, 2024 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the… | ||
| CVE-2021-47621 | Hig | 0.42 | 7.5 | 0.01 | Jun 21, 2024 | ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks. | ||
| CVE-2024-4357 | Med | 0.42 | 6.5 | 0.01 | May 15, 2024 | An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing. | ||
| CVE-2023-51605 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to… | ||
| CVE-2023-51604 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to… | ||
| CVE-2023-51602 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to… | ||
| CVE-2023-51601 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to… | ||
| CVE-2023-51600 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to… | ||
| CVE-2023-42035 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Visualware MyConnection Server. Authentication is not required… | ||
| CVE-2023-39472 | Med | 0.42 | 6.5 | 0.01 | May 3, 2024 | Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automation Ignition. Authentication is required… | ||
| CVE-2023-52239 | Med | 0.42 | 6.5 | 0.00 | Feb 6, 2024 | The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport. | ||
| CVE-2024-23525 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2024 | The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig. | ||
| CVE-2023-45139 | Hig | 0.42 | 7.5 | 0.01 | Jan 10, 2024 | fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed.… | ||
| CVE-2022-34832 | Med | 0.42 | 6.5 | 0.01 | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. | ||
| CVE-2023-41932 | Med | 0.42 | 6.5 | 0.01 | Sep 6, 2023 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file… | ||
| CVE-2023-35389 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2023 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2023-37942 | Med | 0.42 | 6.5 | 0.01 | Jul 12, 2023 | Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2023-34411 | Hig | 0.42 | 7.5 | 0.01 | Jun 5, 2023 | The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9. | ||
| CVE-2023-28009 | Med | 0.42 | 6.5 | 0.01 | Apr 26, 2023 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. |
- risk 0.42cvss 6.5epss 0.00
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1.
- risk 0.42cvss 7.5epss 0.01
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the…
- risk 0.42cvss 7.5epss 0.01
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
- risk 0.42cvss 6.5epss 0.01
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
- risk 0.42cvss 6.5epss 0.01
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…
- risk 0.42cvss 6.5epss 0.01
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…
- risk 0.42cvss 6.5epss 0.01
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…
- risk 0.42cvss 6.5epss 0.01
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…
- risk 0.42cvss 6.5epss 0.01
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…
- risk 0.42cvss 6.5epss 0.01
Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Visualware MyConnection Server. Authentication is not required…
- risk 0.42cvss 6.5epss 0.01
Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automation Ignition. Authentication is required…
- risk 0.42cvss 6.5epss 0.00
The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.
- risk 0.42cvss 6.5epss 0.01
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
- risk 0.42cvss 7.5epss 0.01
fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed.…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
- risk 0.42cvss 6.5epss 0.01
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file…
- risk 0.42cvss 6.5epss 0.01
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.01
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.42cvss 7.5epss 0.01
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
- risk 0.42cvss 6.5epss 0.01
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.