VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 45 of 69
  • CVE-2023-26058MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.00

    An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created…

  • CVE-2023-26057MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.00

    An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically…

  • CVE-2023-28684MedApr 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-26267MedFeb 21, 2023
    risk 0.42cvss 6.5epss 0.01

    php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.

  • CVE-2023-22832HigFeb 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with…

  • CVE-2022-43430HigOct 19, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-43415HigOct 19, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-2330MedAug 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file,…

  • CVE-2022-31471HigJul 26, 2022
    risk 0.42cvss 7.5epss 0.02

    untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.

  • CVE-2022-34001MedJul 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

  • CVE-2022-29943MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions…

  • CVE-2022-27201MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file…

  • CVE-2022-26661MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through…

  • CVE-2021-43576MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.02

    Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets…

  • CVE-2021-20839MedNov 1, 2021
    risk 0.42cvss 6.5epss 0.01

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.

  • CVE-2021-3869HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2021-20801MedOct 13, 2021
    risk 0.42cvss 6.5epss 0.01

    Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.

  • CVE-2021-34706MedOct 6, 2021
    risk 0.42cvss 6.4epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is…

  • CVE-2021-35201MedSep 30, 2021
    risk 0.42cvss 6.5epss 0.01

    NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.

  • CVE-2021-41098HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.01

    Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who parse untrusted documents using any of…