CVE-2019-15160
19.08.2019, 06:15
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
Vendor | Product | Version |
---|---|---|
kbrw | sweet_xml | 𝑥 ≤ 0.6.6 |
𝑥
= Vulnerable software versions