PT-2022-26190 · Dragonfly · Dragonfly
Joshuasing
·
Published
2022-12-27
·
Updated
2023-01-06
·
CVE-2022-41967
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Dragonfly version 0.3.0-SNAPSHOT
Description
The issue concerns a Java runtime dependency management library that does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This can be avoided by not trying to resolve
SNAPSHOT versions, as the library only parses XML for such versions.Recommendations
For Dragonfly version 0.3.0-SNAPSHOT, update to version 0.3.1-SNAPSHOT to resolve the issue. As a temporary workaround, consider avoiding the resolution of
SNAPSHOT versions to minimize the risk of exploitation.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dragonfly