Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-0217


It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).


Published

2022-08-26T18:15:08.833

Last Modified

2024-11-21T06:38:09.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-776
  • Type: Primary
    CWE-611
    CWE-776

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application prosody prosody < 0.11.12 Yes

References