First published: Thu Nov 30 2023(Updated: )
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon. This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Cocoon | >=2.2.0<2.3.0 | |
maven/org.apache.cocoon:cocoon | >=2.2.0<2.3.0 | 2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-49733.
The title of the vulnerability is 'Apache Cocoon s StreamGenerator is vulnerable to XXE injection'.
The vulnerability is an Improper Restriction of XML External Entity (XXE) Reference vulnerability in Apache Cocoon.
Users are recommended to upgrade to version 2.3.0 of Apache Cocoon, which fixes the issue.
The vulnerability is associated with CWE-611.