Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7238
HistoryAug 06, 2018 - 2:11 a.m.

XML External Entities (XXE)

2018-08-0602:11:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.024

Percentile

90.1%

libxml2 is vulnerable to XML external entity attacks. The xmlParserHandlePEReference function in parser.c allows external parameter entities to be loaded regardless of whether entity substitution or validation is enabled. This allows an attacker to cause a denial of service condition or an information leak using a crafted XML document.