PT-2024-11501 · Unknown · Classgraph
Kurtseifried
+1
·
Published
2024-06-21
·
Updated
2024-08-19
·
CVE-2021-47621
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ClassGraph versions prior to 4.8.112
Description
The issue concerns the susceptibility of ClassGraph to XML eXternal Entity (XXE) attacks. This means that an attacker could potentially exploit the software by injecting malicious XML code, leading to unauthorized access to sensitive data or other malicious activities.
Recommendations
For versions prior to 4.8.112, update to version 4.8.112 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external XML entities to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Classgraph