Description
In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35072 | In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests. |
References
| Link | Providers |
|---|---|
| https://bugs.eclipse.org/580542 |
|
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-03T00:52:59.807Z
Reserved: 2022-08-16T00:00:00.000Z
Link: CVE-2022-2838
No data.
Status : Modified
Published: 2022-08-16T10:15:08.360
Modified: 2024-11-21T07:01:46.940
Link: CVE-2022-2838
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD