First published: Tue Aug 16 2022(Updated: )
In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Sphinx | >=0.7.0<0.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2838 is a vulnerability in Eclipse Sphinx™ before version 0.13.1 that allows the injection of arbitrary definitions and access to local files.
CVE-2022-2838 affects Eclipse Sphinx™ versions before 0.13.1 by enabling the injection of arbitrary definitions and allowing access to local files.
CVE-2022-2838 has a severity rating of 5.3, which is considered medium.
CVE-2022-2838 can be exploited by injecting arbitrary definitions and accessing local files via Eclipse Sphinx™ before version 0.13.1.
Yes, a fix is available for CVE-2022-2838 by upgrading to version 0.13.1 of Eclipse Sphinx™.