Lucene search

K
githubGitHub Advisory DatabaseGHSA-JWWR-FJGH-CV2X
HistoryMay 13, 2022 - 1:05 a.m.

Improper Restriction of XML External Entity Reference in Castor

2022-05-1301:05:37
CWE-611
GitHub Advisory Database
github.com
12
castor
xerces sax parser
xml external entity
xxe attacks
crafted xml document
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.016

Percentile

87.6%

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

Affected configurations

Vulners
Node
org.codehaus.castor\Matchcastor

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.016

Percentile

87.6%