Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2023-09-06 CVE-2023-41933 XXE vulnerability in Jenkins JOB Configuration History
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.8
2023-09-05 CVE-2023-35892 XXE vulnerability in IBM Financial Transaction Manager 3.2.4
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2023-09-01 CVE-2023-40239 XXE vulnerability in Lexmark products
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure.
network
low complexity
lexmark CWE-611
7.5
2023-08-31 CVE-2023-41034 XXE vulnerability in Eclipse Leshan
Eclipse Leshan is a device management server and client Java implementation.
network
low complexity
eclipse CWE-611
critical
9.8
2023-08-25 CVE-2023-24620 XXE vulnerability in Esotericsoftware Yamlbeans
An issue was discovered in Esoteric YamlBeans through 1.15.
local
low complexity
esotericsoftware CWE-611
5.5
2023-08-22 CVE-2022-48565 XXE vulnerability in multiple products
An XML External Entity (XXE) issue was discovered in Python through 3.9.1.
network
low complexity
python debian CWE-611
critical
9.8
2023-08-21 CVE-2022-46751 XXE vulnerability in Apache IVY
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used. This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven.
network
low complexity
apache CWE-611
8.2
2023-08-11 CVE-2023-0871 XXE vulnerability in Opennms Horizon and Meridian
XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.
low complexity
opennms CWE-611
6.1
2023-08-11 CVE-2023-3823 XXE vulnerability in multiple products
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded.
network
low complexity
php fedoraproject debian CWE-611
7.5
2023-08-10 CVE-2023-32567 XXE vulnerability in Ivanti Avalanche
Ivanti Avalanche decodeToMap XML External Entity Processing.
network
low complexity
ivanti CWE-611
critical
9.8