apache/incubator-kie-drools
Releases489
Frequency1 week 4 days
Last Release
Stars6.29K
Drools is a rule engine, DMN engine and complex event processing (CEP) engine for Java
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| — | 9.8 CRITICAL | 7.5 HIGH | ||
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | ||||
| — | — | 7.5 HIGH | ||
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file. | ||||