PT-2022-11391 · Drools+1 · Drools+1
Published
2022-06-16
·
Updated
2022-10-26
·
CVE-2021-41411
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
drools versions prior to 7.60
Description
The issue is related to an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Recommendations
For drools versions prior to 7.60, update to a version that correctly utilizes the Validator class to prevent XXE injection.
As a temporary workaround, consider restricting the use of KieModuleMarshaller.java until a patch is available.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Drools