CVE-2022-1331: Delta Electronics DMARS Improper Restriction of XML External Entity Reference
Published May 3, 2022
·Updated
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
Affected Software
2 affected componentsFixes available
Deltaww Dmars<2.1.10.24
Delta Electronics DMARS<2.1.10.24
2.1.10.24
Event History
May 3, 2022
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1331?
The severity of CVE-2022-1331 is classified as medium due to its potential for unauthorized information disclosure.
2
How do I fix CVE-2022-1331?
To fix CVE-2022-1331, upgrade DMARS to version 2.1.10.24 or later.
3
What are the effects of CVE-2022-1331?
CVE-2022-1331 can lead to unauthorized information disclosure through improper regulation of XML external entities.
4
Which versions of DMARS are affected by CVE-2022-1331?
All versions of DMARS prior to 2.1.10.24 are affected by CVE-2022-1331.
5
Is CVE-2022-1331 a critical vulnerability?
CVE-2022-1331 is not considered critical, but it still poses a risk that should be mitigated.