CVE-2014-0119
Missing XML Validation in Apache Tomcat
EPSS 7.6%
描述
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.
如何修補 CVE-2014-0119
要修補 CVE-2014-0119,請將受影響套件升級到下列已修補版本。
- —升級至 6.0.40 或更新版本
- —升級至 6.0.40 或更新版本
- —升級至 6.0.40 或更新版本
CVE-2014-0119 正在被利用嗎?
中等 — EPSS 為 7.6%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 6.0.40
- from 0, < 6.0.40
- from 0, < 6.0.40