CVE-2017-1000061

HIGH

xmlsec <1.2.23 - Info Disclosure/DoS

Title source: llm
STIX 2.1

Description

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2492
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/lsh123/xmlsec/issues/43

Scores

CVSS v3 7.1
EPSS 0.0134
EPSS Percentile 67.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-611
Status published
Products (1)
xmlsec_project/xmlsec < 1.2.23
Published Jul 17, 2017
Tracked Since Feb 18, 2026