VulnerabilityModified
CVE-2022-2414
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.
HIGH 7.5EPSS 85.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 85.61% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- dogtagpki/dogtagpki
- Source
- secalert@redhat.com
References
- https://github.com/dogtagpki/pki/pull/4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/4021Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.