PT-2022-18280 · Unknown · Cvrf-Csaf-Converter
Published
2022-03-15
·
Updated
2023-08-08
·
CVE-2022-27193
CVSS v3.1
6.1
Medium
| Vector | AC:L/AV:L/A:L/C:H/I:N/PR:N/S:U/UI:R |
Name of the Vulnerable Software and Affected Versions
CVRF-CSAF-Converter versions prior to 1.0.0-rc2
Description
The issue allows for the inclusion of arbitrary local file content into the generated output document due to XML External Entities (XXE). This can be exploited by an attacker to disclose information from the system running the converter.
Recommendations
For versions prior to 1.0.0-rc2, update to version 1.0.0-rc2 or later to resolve the issue.
Fix
XXE
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cvrf-Csaf-Converter