Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6086
HistoryApr 11, 2018 - 7:01 a.m.

XML External Entity (XXE)

2018-04-1107:01:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.005 Low

EPSS

Percentile

77.1%

libxml2 is vulnerable to XML External Entity (XXE) attacks. The library does not disable document type declaration by default, allowing a malicious user to pass a file that can lead to arbitrary code execution or information disclosure.

CPENameOperatorVersion
libxml2.sole2.9.4
libxml2le2.7.8.7