← Back

CVE-2022-2838

nvd nist
Published: Aug 16, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

Affected (1)

Products: Eclipse: Sphinx
1 product
Sphinx
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.7.0 to 0.13.1

References (2)

Source: emo@eclipse.org
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.