First published: Tue May 03 2022(Updated: )
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dmars | <2.1.10.24 | |
Delta Electronics | <2.1.10.24 | 2.1.10.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1331 is classified as medium due to its potential for unauthorized information disclosure.
To fix CVE-2022-1331, upgrade DMARS to version 2.1.10.24 or later.
CVE-2022-1331 can lead to unauthorized information disclosure through improper regulation of XML external entities.
All versions of DMARS prior to 2.1.10.24 are affected by CVE-2022-1331.
CVE-2022-1331 is not considered critical, but it still poses a risk that should be mitigated.