CRITICAL 9.8 Maven
XML External Entity Reference in Hazelcast
GHSA-99wh-973f-779p · CVE-2022-0265
Published · Modified
Description
The AbstractXmlConfigRootTagRecognizer() function makes use of SAXParser generated from a SAXParserFactory with no FEATURE_SECURE_PROCESSING set, allowing for XXE attacks.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-0265
- WEB https://github.com/hazelcast/hazelcast/pull/20407
- WEB https://github.com/hazelcast/hazelcast/commit/4d6b666cd0291abd618c3b95cdbb51aa4208e748
- WEB https://github.com/hazelcast/hazelcast
- WEB https://huntr.dev/bounties/d63972a2-b910-480a-a86b-d1f75d24d563
Ready to move
Start Securing
Free, no credit card | First findings in minutes