CVE-2017-6344: XEE
Published Feb 27, 2017
·Updated
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
Affected Software
1 affected component
Grails PDF Plugin=0.6
Event History
Feb 27, 2017
CVE Published
via MITRE·07:25 AM
Data Sourced
via MITRE·07:25 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6344?
CVE-2017-6344 is classified as a high-severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2017-6344?
To mitigate CVE-2017-6344, upgrade the Grails PDF Plugin to the latest version that does not contain this vulnerability.
3
What systems are affected by CVE-2017-6344?
CVE-2017-6344 specifically affects the Grails PDF Plugin version 0.6.
4
What kind of attack can exploit CVE-2017-6344?
CVE-2017-6344 can be exploited by attackers using crafted XML documents to perform XML External Entity attacks.
5
What are the consequences of CVE-2017-6344?
Exploitation of CVE-2017-6344 can lead to unauthorized access to sensitive files on the server.