CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
EPSS
Percentile
44.4%
php81 is vulnerable to XML External Entities (XXE). The program handles XML documents that include URIs that resolve to external resources, resulting in inaccurate output and posing problems for the end product.
github.com/php/php-src/security/advisories/GHSA-3qrf-m4j2-pcrr
lists.debian.org/debian-lts-announce/2023/09/msg00002.html
lists.fedoraproject.org/archives/list/[email protected]/message/7NBF77WN6DTVTY2RE73IGPYD6M4PIAWA/
secdb.alpinelinux.org/v3.17/community.yaml
security.netapp.com/advisory/ntap-20230825-0001/