7.5

CVE-2021-33813

Medienbericht
Exploit

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JdomJdom Version <= 2.0.6
ApacheSolr Version8.8.1
ApacheSolr Version8.9
ApacheTika Version1.25
DebianDebian Linux Version9.0
FedoraprojectFedora Version35
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.251
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://alephsecurity.com/vulns/aleph-2021003
Third Party Advisory
Exploit
https://github.com/hunterhacker/jdom/releases
Third Party Advisory
Release Notes