xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
References
Configurations
Information
Published : 2017-07-17 06:18
Updated : 2021-06-14 11:15
NVD link : CVE-2017-1000061
Mitre link : CVE-2017-1000061
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
xmlsec_project
- xmlsec