CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 65 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56324 | Hig | 0.00 | 7.1 | 0.01 | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability… | ||
| CVE-2024-56322 | Hig | 0.00 | 7.2 | 0.01 | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when… | ||
| CVE-2024-28198 | Med | 0.00 | 4.6 | 0.00 | Mar 11, 2024 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configured system user and SSRF. The problem is… | ||
| CVE-2021-33950 | Hig | 0.00 | 7.5 | 0.01 | Feb 17, 2023 | An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function. | ||
| CVE-2021-4295 | Med | 0.00 | 5.5 | 0.01 | Dec 29, 2022 | A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the… | ||
| CVE-2022-41967 | Hig | 0.00 | 7.0 | 0.01 | Dec 28, 2022 | Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT`… | ||
| CVE-2022-4607 | Med | 0.00 | 5.5 | 0.01 | Dec 18, 2022 | A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version 5.2.1 is able to address this issue. The… | ||
| CVE-2021-41411 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | ||
| CVE-2021-42646 | — | Cri | 0.00 | 9.1 | 0.04 | May 11, 2022 | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,… | |
| CVE-2021-3836 | Med | 0.00 | 5.5 | 0.01 | Dec 14, 2021 | dbeaver is vulnerable to Improper Restriction of XML External Entity Reference | ||
| CVE-2021-44556 | Cri | 0.00 | 9.1 | 0.01 | Dec 8, 2021 | National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS. | ||
| CVE-2021-21701 | Med | 0.00 | 6.5 | 0.02 | Nov 12, 2021 | Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2020-25911 | Cri | 0.00 | 9.1 | 0.02 | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS). | ||
| CVE-2021-32925 | Med | 0.00 | 6.5 | 0.02 | May 13, 2021 | admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. | ||
| CVE-2021-27736 | Med | 0.00 | 6.5 | 0.01 | Apr 22, 2021 | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely. | ||
| CVE-2021-21266 | Med | 0.00 | 6.4 | 0.01 | Feb 1, 2021 | openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal information like the… | ||
| CVE-2021-23901 | Cri | 0.00 | 9.1 | 0.04 | Jan 25, 2021 | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's… | ||
| CVE-2020-15232 | Cri | 0.00 | 9.3 | 0.01 | Oct 2, 2020 | In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style. | ||
| CVE-2020-25020 | Cri | 0.00 | 9.8 | 0.03 | Aug 29, 2020 | MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. | ||
| CVE-2020-10990 | Cri | 0.00 | 9.8 | 0.01 | Mar 27, 2020 | An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. |
- risk 0.00cvss 7.1epss 0.01
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability…
- risk 0.00cvss 7.2epss 0.01
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when…
- risk 0.00cvss 4.6epss 0.00
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configured system user and SSRF. The problem is…
- risk 0.00cvss 7.5epss 0.01
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
- risk 0.00cvss 5.5epss 0.01
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the…
- risk 0.00cvss 7.0epss 0.01
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT`…
- risk 0.00cvss 5.5epss 0.01
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version 5.2.1 is able to address this issue. The…
- risk 0.00cvss 9.8epss 0.01
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
- risk 0.00cvss 9.1epss 0.04
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,…
- risk 0.00cvss 5.5epss 0.01
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.00cvss 9.1epss 0.01
National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.
- risk 0.00cvss 6.5epss 0.02
Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.00cvss 9.1epss 0.02
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
- risk 0.00cvss 6.5epss 0.02
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
- risk 0.00cvss 6.5epss 0.01
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
- risk 0.00cvss 6.4epss 0.01
openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal information like the…
- risk 0.00cvss 9.1epss 0.04
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's…
- risk 0.00cvss 9.3epss 0.01
In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
- risk 0.00cvss 9.8epss 0.03
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
- risk 0.00cvss 9.8epss 0.01
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.