CVE-2020-10991: XEE
Withdrawn Advisory This advisory has been withdrawn because it does not affected a package in a supported ecosystem. This link has been maintained to preserve external references.
Original Description
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10991?
CVE-2020-10991 is classified as a high severity vulnerability due to the potential for XML External Entity (XXE) attacks.
How do I fix CVE-2020-10991?
To mitigate CVE-2020-10991, upgrade to version 1.3.1 or later of the MuleSoft APIkit.
What types of attacks are possible with CVE-2020-10991?
CVE-2020-10991 allows for XML External Entity attacks which can lead to exposure of sensitive data or system compromise.
Which versions of the MuleSoft APIkit are affected by CVE-2020-10991?
CVE-2020-10991 affects MuleSoft APIkit versions up to and including 1.3.0.
Is CVE-2020-10991 contextually relevant for all MuleSoft users?
Yes, CVE-2020-10991 is a concern for all users of affected versions of the MuleSoft APIkit that process XML.