PT-2024-11501 · Unknown · Classgraph

Kurtseifried

+1

·

Published

2024-06-21

·

Updated

2024-08-19

·

CVE-2021-47621

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ClassGraph versions prior to 4.8.112
Description The issue concerns the susceptibility of ClassGraph to XML eXternal Entity (XXE) attacks. This means that an attacker could potentially exploit the software by injecting malicious XML code, leading to unauthorized access to sensitive data or other malicious activities.
Recommendations For versions prior to 4.8.112, update to version 4.8.112 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external XML entities to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2021-47621
GHSA-V2XM-76PQ-PHCF

Affected Products

Classgraph