CVE-2021-42776

HIGH

CloverDX Server < 5.11.2 and 5.12.x < 5.12.1 - XML External Entity Injection via Configuration Import

Title source: llm
STIX 2.1

Description

CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.cloverdx.com/releases/

Scores

CVSS v3 7.7
EPSS 0.0077
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (3)
cloverdx/cloverdx 5.12.0
cloverdx/cloverdx 5.12.1
cloverdx/cloverdx < 5.11.2
Published Dec 01, 2021
Tracked Since Feb 18, 2026