CVE-2020-11991
11.09.2020, 14:15
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.Enginsight
Vendor | Product | Version |
---|---|---|
apache | cocoon | 2.1 ≤ 𝑥 ≤ 2.1.12 |
𝑥
= Vulnerable software versions