First published: Wed Dec 01 2021(Updated: )
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloverdx Cloverdx | <5.11.2 | |
Cloverdx Cloverdx | =5.12.0 | |
Cloverdx Cloverdx | =5.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42776 is a vulnerability in CloverDX Server before 5.11.2 and 5.12.x before 5.12.1 that allows XXE (XML External Entity) during configuration import.
CVE-2021-42776 affects CloverDX Server versions before 5.11.2 and 5.12.x before 5.12.1.
CVE-2021-42776 has a severity rating of 7.7 (High).
To fix CVE-2021-42776, update your CloverDX Server to version 5.11.2 or higher, or version 5.12.1 or higher.
You can find more information about CVE-2021-42776 at the following references: [Reference 1](https://support.cloverdx.com/releases/), [Reference 2](https://support1.cloverdx.com/hc/en-us/articles/4411125429010).