CVE-2017-1000061

lsh123/xmlsec
on github

Published

Severity

CVSS v3:
7.1 HIGH
CVSS v2:
5.8 MEDIUM

Description

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:xmlsec_project:xmlsec:*:*:*:*:*:*:*:*n/a1.2.23 (including)*

External Links