Lucene search

K
osvGoogleOSV:GHSA-QM4X-CH5W-GR62
HistoryMay 17, 2022 - 4:42 a.m.

XXE in SabreDAV

2022-05-1704:42:42
Google
osv.dev
8
sabredav
xxe
vulnerability
owncloud
xml external entity
remote attack
denial of service

AI Score

7.2

Confidence

High

EPSS

0.005

Percentile

77.0%

SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

AI Score

7.2

Confidence

High

EPSS

0.005

Percentile

77.0%