CVE-2021-1628: XEE
Published Mar 26, 2021
·Updated
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.
Affected Software
1 affected component
Salesforce Mule>=4.0.0<=4.2.2
Event History
Mar 26, 2021
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-1628?
The severity of CVE-2021-1628 is rated as critical with a score of 9.8.
2
How does CVE-2021-1628 impact MuleSoft customers?
CVE-2021-1628 affects certain versions of Mule runtime components, potentially impacting both CloudHub and on-premise customers.
3
What versions of Mule runtime are affected by CVE-2021-1628?
The affected versions are Mule 4.x runtimes released before February 2, 2021.