CVE-2021-1630: XEE
Published Aug 5, 2021
·Updated
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
Affected Software
1 affected component
Salesforce Mule>=3.0.0<4.3.0
Event History
Aug 5, 2021
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-1630?
The severity of CVE-2021-1630 is high with a CVSS score of 7.5.
2
How does CVE-2021-1630 affect customers?
CVE-2021-1630 affects CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
3
How can I check if my version of Salesforce Mule is affected by CVE-2021-1630?
If you are using Salesforce Mule versions between 3.0.0 and 4.3.0, your system may be affected by CVE-2021-1630.
4
What is the vulnerability type of CVE-2021-1630?
CVE-2021-1630 is an XML external entity (XXE) vulnerability.
5
How can I mitigate the risk of CVE-2021-1630?
To mitigate CVE-2021-1630, consider applying updates or patches provided by Salesforce for the affected Mule runtime component versions.