kiegroup/drools
Releases278
Frequency2 weeks 4 days
Last Release
Stars166
This repository is a fork of apache/incubator-kie-drools. Please use upstream repository for development.
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 7.6.0 | 9.8 CRITICAL | 7.5 HIGH | ||
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | ||||