In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2017-07-19T15:00:00Z
Updated: 2024-09-16T16:47:49.975Z
Reserved: 2016-08-12T00:00:00
Link: CVE-2016-6798
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-07-19T15:29:00.213
Modified: 2024-11-21T02:56:50.940
Link: CVE-2016-6798
Redhat
No data.