PT-2020-12475 · Mulesoft · Mulesoft Apikit

N33Dle

+1

·

Published

2020-03-26

·

Updated

2022-05-24

·

CVE-2020-10991

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mulesoft APIkit versions prior to 1.3.1
Description The issue allows XXE (XML External Entity) attacks due to a problem in the validation process, specifically in the RestXmlSchemaValidator.java file. This could potentially affect a large number of devices worldwide, although the exact number is not specified.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider disabling the validation/RestXmlSchemaValidator.java component until a patch is available. Restrict access to XML schema validation to minimize the risk of exploitation.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10991
GHSA-JFFQ-528J-MP6C

Affected Products

Mulesoft Apikit