CVE-2016-3674
🟡 Monitoruj
Wielokrotne podatności XXE w XStream umożliwiają zdalne odczytywanie plików.
CVSS
7.5
EPSS
8.2%
Exploit
none
Vendor
fedoraproject
Opis źródłowy (NVD)
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
xxe
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 8.2% |
| Opublikowano (NVD) | 2016-05-17 14:08:03 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:05 UTC |
Referencje
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html ([email protected]) [Broken Link, Third Party Advisory]
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.html ([email protected]) [Broken Link, Third Party Advisory]
- http://rhn.redhat.com/errata/RHSA-2016-2822.html ([email protected]) [Broken Link]
- http://rhn.redhat.com/errata/RHSA-2016-2823.html ([email protected]) [Broken Link]
- http://www.debian.org/security/2016/dsa-3575 ([email protected]) [Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2016/03/25/8 ([email protected]) [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2016/03/28/1 ([email protected]) [Mailing List, Third Party Advisory]
- http://www.securityfocus.com/bid/85381 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1036419 ([email protected]) [Third Party Advisory, VDB Entry]
- http://x-stream.github.io/changes.html#1.4.9 ([email protected]) [Vendor Advisory]
- https://github.com/x-stream/xstream/issues/25 ([email protected]) [Vendor Advisory]