Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Cocoon
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-11991 1 Apache 1 Cocoon 2020-09-17 5.0 MEDIUM 7.5 HIGH
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.