CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-23901

CVSS 9.1v3.1pub. 2021-01-25upd. 2024-11-21

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Nutch 1.18.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Nutch

    APP
    Apache
    < 1.18
  • Netapp Snap Creator Framework

    APP
    Netapp
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)

CVE-2021-23926CRITICAL9.1PL ✓same product

Apache XMLBeans — podatność na XML Entity Expansion (XEE)

CVE-2020-10683CRITICAL9.8PL ✓same product

XXE w bibliotece dom4j — domyślne zezwolenie na zewnętrzne encje XML

CVE-2018-18311CRITICAL9.8PL ✓same product

Buffer overflow w Perl przez spreparowane wyrażenie regularne

CVE-2018-18313CRITICAL9.1PL ✓same product

Perl: buffer over-read w obsłudze wyrażeń regularnych — wyciek pamięci