Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8058
HistoryDec 21, 2018 - 3:36 a.m.

XML External Entity Injection (XXE)

2018-12-2103:36:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.002

Percentile

61.3%

Fess is vulnerable to XML external entity injection (XXE). The library does not prevent the GSA XML file parser from processing the malicious GSA XML files injected by the attacker.

EPSS

0.002

Percentile

61.3%

Related for VERACODE:8058