Lucene search

K
cvelist@huntrdevCVELIST:CVE-2021-3878
HistoryOct 15, 2021 - 1:40 p.m.

CVE-2021-3878 Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp

2021-10-1513:40:21
CWE-611
@huntrdev
www.cve.org
3
corenlp
vulnerability
xml entity reference

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.004

Percentile

72.7%

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CNA Affected

[
  {
    "product": "stanfordnlp/corenlp",
    "vendor": "stanfordnlp",
    "versions": [
      {
        "lessThanOrEqual": "4.3.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.004

Percentile

72.7%

Related for CVELIST:CVE-2021-3878