csaf-tools/CVRF-CSAF-Converter

csaf-tools/CVRF-CSAF-Converter

Releases9
Frequency1 week 1 day
Last Release
Stars9
A CVRF CSAF Converter, taking care about OASIS specification.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.