Releases278
Frequency2 weeks 4 days
Last Release
Stars166
This repository is a fork of apache/incubator-kie-drools. Please use upstream repository for development.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 7.6.09.8 CRITICAL7.5 HIGH

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.