PT-2022-13080 · Hazelcast · Hazelcast

Kwart

·

Published

2022-03-03

·

Updated

2022-04-29

·

CVE-2022-0265

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hazelcast/hazelcast versions 5.1-BETA-1 through 5.1
Description The issue is related to an improper restriction of XML external entity references, allowing for XXE attacks. The AbstractXmlConfigRootTagRecognizer() function uses a SAXParser generated from a SAXParserFactory with no FEATURE SECURE PROCESSING set. This enables potential exploitation.
Recommendations For versions 5.1-BETA-1 through 5.1, update to version 5.1 or later to resolve the issue. As a temporary workaround, consider setting FEATURE SECURE PROCESSING in the SAXParserFactory to prevent XXE attacks.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0265
GHSA-99WH-973F-779P

Affected Products

Hazelcast