Showing 1 vulnerability on this page for Eclipse Lyo

Signals CISA KEV Ransomware Nuclei
The Eclipse Foundation vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

XML External Entity Reference in Eclipse Lyo

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.

CWE-611Jul 7, 2022
CVSS5.3v3.1EPSS0.953%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX