Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47285
HistoryMay 31, 2024 - 6:39 a.m.

XML Entity Expansion

2024-05-3106:39:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1
vulnerability
xml
symfony
libxml2
quadratic blowup attacks
denial of service
memory sink
software

7 High

AI Score

Confidence

High

symfony/symfony is vulnerable to XML Entity Expansion. The vulnerability is due to all extensions that use libxml2 having no defense against Quadratic Blowup Attacks, which involve defining a long entity that is repeatedly referenced within the XML document, thus creating a potential memory sink for Denial of Service attacks targeting host memory.

7 High

AI Score

Confidence

High