Vulnerabilities > CVE-2021-41411 - XXE vulnerability in Redhat Drools 6.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |