CVE-2021-41042

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
07/07/2022
Last modified:
07/11/2023

Description

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:lyo:*:*:*:*:*:*:*:* 1.0.0 (including) 4.1.0 (including)


References to Advisories, Solutions, and Tools