CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2021-43142 CRITICAL
jox < 1.16 - XML External Entity Injection via JOXSAXBeanInput readObject
CVSS 9.8
CVE-2021-33208 HIGH
MashZone NextGen <10.7 - XML External Entity
CVSS 7.2
CVE-2021-44477 HIGH
GE ToolBoxST < 07.09.07c - XML External Entity Injection via DTD Parameter Entities
CVSS 7.5
CVE-2021-43090 CRITICAL
predic8 soa_model < 1.6.4 - XML External Entity Injection in WSDLParser
CVSS 9.8
CVE-2021-42194 HIGH
EyouCMS 1.5.4-UTF8-SP3 - XXE via wechat_return XML Parsing
CVSS 7.2
CVE-2021-46365 HIGH
Magnolia CMS < 6.2.4 - XML External Entity Injection via XLF File
CVSS 7.8
CVE-2021-46660 CRITICAL
Signiant Manager+Agents <15.1 - XSS
CVSS 9.8
CVE-2021-40722 CRITICAL
AEM Forms Cloud Service <6.5.10.0 - XXE Injection
CVSS 9.8
CVE-2021-42560 HIGH
MITRE Caldera 2.9.0 - XML External Entity Injection via Debrief Plugin SVG Parameter
CVSS 8.8
CVE-2021-44028 MEDIUM
Quest KACE Desktop Authority 10.0-11.1 - XML External Entity Injection via log4net Configuration
CVSS 5.5
CVE-2021-45096 MEDIUM
KNIME Analytics Platform < 4.5.0 - XML External Entity Injection via Crafted Workflow File
CVSS 4.7
CVE-2021-3836 MEDIUM
DBeaver <=21.2.3 - XML External Entity Injection
CVSS 5.5
CVE-2021-23463 HIGH
H2 < 2.0.202 - XXE
CVSS 8.1
CVE-2021-44557 CRITICAL
multiNER < 08-25-2021 - XML External Entity Injection in ner.py
CVSS 9.1
CVE-2021-44556 CRITICAL
kb/digger < 08-25-2021 - XML External Entity Injection
CVSS 9.1
CVE-2021-42776 HIGH
CloverDX Server < 5.11.2 and 5.12.x < 5.12.1 - XML External Entity Injection via Configuration Import
CVSS 7.7
CVE-2021-44147 MEDIUM
Claris FileMaker Pro and Server < 19.4.1 - XML External Entity Injection via Crafted XML/Excel Document
CVSS 5.5
CVE-2021-43577 HIGH
Jenkins OWASP Dependency-Check Plugin <5.1.1 - XXE
CVSS 7.1
CVE-2021-43576 MEDIUM
Jenkins pom2config Plugin <1.2 - XXE
CVSS 6.5
CVE-2021-21701 MEDIUM
Jenkins Performance Plugin < 3.20 - XML External Entity Injection
CVSS 6.5
CVE-2021-36172 MEDIUM
FortiPortal <6.0.6 - DoS/Info Disclosure
CVSS 4.3
CVE-2021-20839 MEDIUM
Office Server Document Converter <7.2MR4, <7.1MR7 - DoS
CVSS 6.5
CVE-2021-20838 HIGH
Office Server Document Converter <7.2MR4, <7.1MR7 - DoS
CVSS 7.5
CVE-2021-3869 HIGH
Stanford CoreNLP <=4.3.1 - XML External Entity Injection
CVSS 7.5
CVE-2021-3878 CRITICAL
Stanford CoreNLP <=4.3.1 - XML External Entity Injection
CVSS 9.8
Details
Vulnerabilities 1,250