CVE-2022-27193

CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0:dev1:*:*:*:*:*:*
cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0:dev2:*:*:*:*:*:*
cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0:dev3:*:*:*:*:*:*
cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0:rc1:*:*:*:*:*:*

Information

Published : 2022-03-14 22:15

Updated : 2022-03-21 11:52


NVD link : CVE-2022-27193

Mitre link : CVE-2022-27193


JSON object : View

CWE
CWE-552

Files or Directories Accessible to External Parties

Advertisement

dedicated server usa

Products Affected

cvrf-csaf-converter_project

  • cvrf-csaf-converter