CVE-2020-11991

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/09/2020
Last modified:
17/09/2020

Description

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:cocoon:*:*:*:*:*:*:*:* 2.1 (including) 2.1.12 (including)