PT-2021-24204 · Knime · Knime Analytics Platform

Dawid Czarnecki

·

Published

2021-12-16

·

Updated

2023-09-28

·

CVE-2021-45096

CVSS v3.1

4.7

Medium

VectorAC:L/AV:N/A:N/C:L/I:N/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions: KNIME Analytics Platform versions prior to 4.5.0
Description: The issue concerns an external XML entity injection (XXE) vulnerability. It can be exploited via a crafted workflow file (.knwf).
Recommendations: For versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted workflow files (.knwf) to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2021-45096

Affected Products

Knime Analytics Platform