Description
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
References (4)
Core 4
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/f1ae5779-b406-4594-a8a3-d089c68d6e70
Patch x_refsource_misc
https://github.com/liquibase/liquibase/commit/33d9d925082097fb1a3d2fc8e44423d964cd9381
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2022.html
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/14
Scores
CVSS v3
9.8
EPSS
0.0010
EPSS Percentile
27.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (3)
liquibase/liquibase
< 4.8.0
oracle/sqlcl
19c
org.liquibase/liquibase-core
0 - 4.8.0Maven
Published
Mar 04, 2022
Tracked Since
Feb 18, 2026