xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
References
Configurations
Information
Published : 2017-07-17 13:18
Updated : 2021-06-14 18:15
NVD link : CVE-2017-1000061
Mitre link : CVE-2017-1000061
JSON object : View
Products Affected
xmlsec_project
- xmlsec
CWE
CWE-611
Improper Restriction of XML External Entity Reference
