PT-2022-11391 · Drools+1 · Drools+1

Published

2022-06-16

·

Updated

2022-10-26

·

CVE-2021-41411

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions drools versions prior to 7.60
Description The issue is related to an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Recommendations For drools versions prior to 7.60, update to a version that correctly utilizes the Validator class to prevent XXE injection. As a temporary workaround, consider restricting the use of KieModuleMarshaller.java until a patch is available.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2021-41411
GHSA-RC57-9R3X-98CQ
SUSE-SU-2022:3313-1
SUSE-SU-2022:3314-1
SUSE-SU-2022:3750-1
SUSE-SU-2022:3761-1

Affected Products

Suse
Drools