VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 65 of 67
  • CVE-2024-56324HigJan 3, 2025
    risk 0.00cvss 7.1epss 0.01

    GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability…

  • CVE-2024-56322HigJan 3, 2025
    risk 0.00cvss 7.2epss 0.01

    GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when…

  • CVE-2024-28198MedMar 11, 2024
    risk 0.00cvss 4.6epss 0.00

    OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configured system user and SSRF. The problem is…

  • CVE-2021-33950HigFeb 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.

  • CVE-2021-4295MedDec 29, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the…

  • CVE-2022-41967HigDec 28, 2022
    risk 0.00cvss 7.0epss 0.01

    Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT`…

  • CVE-2022-4607MedDec 18, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version 5.2.1 is able to address this issue. The…

  • CVE-2021-41411CriJun 16, 2022
    risk 0.00cvss 9.8epss 0.01

    drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

  • CVE-2021-42646CriMay 11, 2022
    risk 0.00cvss 9.1epss 0.04

    XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,…

  • CVE-2021-3836MedDec 14, 2021
    risk 0.00cvss 5.5epss 0.01

    dbeaver is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2021-44556CriDec 8, 2021
    risk 0.00cvss 9.1epss 0.01

    National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.

  • CVE-2021-21701MedNov 12, 2021
    risk 0.00cvss 6.5epss 0.02

    Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-25911CriOct 31, 2021
    risk 0.00cvss 9.1epss 0.02

    A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

  • CVE-2021-32925MedMay 13, 2021
    risk 0.00cvss 6.5epss 0.02

    admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

  • CVE-2021-27736MedApr 22, 2021
    risk 0.00cvss 6.5epss 0.01

    FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.

  • CVE-2021-21266MedFeb 1, 2021
    risk 0.00cvss 6.4epss 0.01

    openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal information like the…

  • CVE-2021-23901CriJan 25, 2021
    risk 0.00cvss 9.1epss 0.04

    An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's…

  • CVE-2020-15232CriOct 2, 2020
    risk 0.00cvss 9.3epss 0.01

    In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.

  • CVE-2020-25020CriAug 29, 2020
    risk 0.00cvss 9.8epss 0.03

    MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

  • CVE-2020-10990CriMar 27, 2020
    risk 0.00cvss 9.8epss 0.01

    An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.