SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-23901

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18.

CRITICAL 9.1EPSS 4.36%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Nutch 1.18.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
4.36% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
apache/nutch · netapp/snap creator framework
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.