CVE-2022-2414: XEE
A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. A remote attacker could potentially use this flaw to retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Upstream PR: https://github.com/dogtagpki/pki/pull/4021
Upstream commit: https://github.com/dogtagpki/pki/commit/4e893243d72ad766558c10c907841f5f9c047055
Other sources
A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-2414?
CVE-2022-2414 is a vulnerability that allows remote attackers to potentially retrieve the content of arbitrary files by exploiting XML external entity (XXE) attacks.
How severe is CVE-2022-2414?
CVE-2022-2414 has a severity rating of 7.5 (high).
Which software is affected by CVE-2022-2414?
CVE-2022-2414 affects pki-core versions 10.5.19, 10.7.5, 10.8.4, 10.11.3, 10.12.5, 11.0.6, 11.1.1, and 11.2.0.
How can I fix CVE-2022-2414?
To fix CVE-2022-2414, update pki-core to version 10.5.19, 10.7.5, 10.8.4, 10.11.3, 10.12.5, 11.0.6, 11.1.1, or 11.2.0.
Where can I find more information about CVE-2022-2414?
More information about CVE-2022-2414 can be found at the following references: [CVE-2022-2414](https://www.cve.org/CVERecord?id=CVE-2022-2414), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-2414), [RedHat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2104676), [RedHat Security Advisory](https://access.redhat.com/errata/RHSA-2022:8915).