Apache Cocoon's StreamGenerator is vulnerable to XXE injection
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.3%
probabilidad de explotación
1.3%top 31% de las CVE
explotación observada
noninguna fuente lo reporta
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
Users are recommended to upgrade to version 2.3.0, which fixes the issue.
Productos afectados
Apache Software Foundation · Apache Cocoon