apache/incubator-kie-drools

apache/incubator-kie-drools

Releases489
Frequency1 week 4 days
Last Release
Stars6.26K
Drools is a rule engine, DMN engine and complex event processing (CEP) engine for Java

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

7.5 HIGH

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.