CVE-2020-11991
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 72%
from disclosure to weapon
Published on NVDSep 11
VulnCheck+1170d
exploitation probability
72%top 1% of all CVEs
observed exploitation
yesVulnCheck
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
Affected products
n/a · Apache Cocoon