Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Apache Subscribe
Filtered by product Cocoon
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-11991 1 Apache 1 Cocoon 2020-09-17 5.0 MEDIUM 7.5 HIGH
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
CVE-2003-1172 1 Apache 1 Cocoon 2017-07-10 5.0 MEDIUM N/A
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.