PT-2022-2076 · Apache · Any23

Liontree0110

·

Published

2022-03-04

·

Updated

2022-03-12

·

CVE-2022-25312

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Any23 versions prior to 2.7
Description An XML external entity (XXE) injection issue was discovered in the Any23 RDFa XSLTStylesheet extractor. This issue allows an attacker to interfere with an application's processing of XML data, potentially enabling them to view files on the application server filesystem and interact with back-end or external systems that the application can access.
Recommendations For versions prior to 2.7, update to Apache Any23 2.7 to resolve the issue. As a temporary workaround, consider restricting the use of the extractor.rdfa.XSLTStylesheet class until a patch is available.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01899
CVE-2022-25312
GHSA-2RMM-87V7-34RJ

Affected Products

Any23