xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
2017-07-17T13:18:17.923
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | xmlsec_project | xmlsec | ≤ 1.2.23 | Yes |