CVE-2019-7722
Improper Restriction of XML External Entity Reference in PMD
8.1
HIGH
CVSS 3.1
EPSS 1.2%
描述
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or request forgery attacks. (PMD 6.x is unaffected because of a 2017-09-15 change.)
如何修補 CVE-2019-7722
要修補 CVE-2019-7722,請將受影響套件升級到下列已修補版本。
- —升級至 6.0.0 或更新版本
CVE-2019-7722 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 6.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |