CVE-2021-41042: XEE
Published Jul 7, 2022
·Updated
In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
Affected Software
1 affected component
Eclipse Lyo>=1.0.0<=4.1.0
Event History
Jul 7, 2022
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41042.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In Eclipse Lyo versions 1.0.0 to 4.1.0 a TransformerFactory is initialized with the defaults that do...'
3
What is the impact of this vulnerability?
This vulnerability allows an attacker to cause an external DTD to be retrieved.
4
What is the severity of CVE-2021-41042?
The severity of CVE-2021-41042 is medium with a CVSS score of 5.3.
5
How can I fix this vulnerability?
To fix this vulnerability, update Eclipse Lyo to a version higher than 4.1.0.