Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22529
HistoryFeb 19, 2020 - 4:27 a.m.

XML External Entity (XXE)

2020-02-1904:27:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.008 Low

EPSS

Percentile

81.1%

quartz is vulnerable to XML external entity (XXE) attacks. The external DTDs and doctype declarations are not disabled by default, allowing an attacker to access system files, or perform requests on behalf of the server via a malicious XML document. The vulnerability also allows an attacker to perform entity expansion attacks which could result in an application crash.

References