Lucene search

K
osvGoogleOSV:GHSA-5V43-55M5-QR8F
HistoryMay 17, 2022 - 3:06 a.m.

getID3 is vulnerable to XML External Entity (XXE)

2022-05-1703:06:13
Google
osv.dev
9
getid3
vulnerability
xxe
attack
owncloud
server
denial of service
remote attackers
arbitrary files

AI Score

8

Confidence

High

EPSS

0.007

Percentile

80.8%

getID3() before 1.9.9, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

AI Score

8

Confidence

High

EPSS

0.007

Percentile

80.8%