PT-2022-18988 · Apache+1 · Apache Xerces-C Xml Parser+1
Zebin
·
Published
2022-08-16
·
Updated
2022-08-18
·
CVE-2022-2838
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Sphinx versions prior to 0.13.1
Description
The issue allows the injection of arbitrary definitions, enabling access to local files and exposing their contents via HTTP requests due to the use of Apache Xerces XML Parser without disabling the processing of referenced external entities.
Recommendations
For Eclipse Sphinx versions prior to 0.13.1, update to version 0.13.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of Apache Xerces XML Parser or restricting its ability to process external entities until a patch is applied.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Xerces-C Xml Parser
Eclipse Sphinx