SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-2838

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via…

MEDIUM 5.3EPSS 0.54%

Does this matter?

Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.54% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
eclipse/sphinx
Source
emo@eclipse.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.