First published: Thu Jul 07 2022(Updated: )
In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Lyo | >=1.0.0<=4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-41042.
The title of this vulnerability is 'In Eclipse Lyo versions 1.0.0 to 4.1.0 a TransformerFactory is initialized with the defaults that do...'
This vulnerability allows an attacker to cause an external DTD to be retrieved.
The severity of CVE-2021-41042 is medium with a CVSS score of 5.3.
To fix this vulnerability, update Eclipse Lyo to a version higher than 4.1.0.