XML External Entity Vulnerability in Mule Runtime by MuleSoft
CVE-2021-1628

9.8CRITICAL

Key Information:

Vendor

Salesforce

Status
Vendor
CVE Published:
26 March 2021

What is CVE-2021-1628?

MuleSoft has identified an XML External Entity (XXE) vulnerability that impacts specific versions of its Mule runtime component. This issue can potentially compromise both CloudHub and on-premise environments for affected users. Organizations utilizing Mule 4.x runtime versions released before February 2, 2021, should be aware of this vulnerability given its implications for data security and application integrity.

Affected Version(s)

Mulesoft Mule 4.x runtime released before February 2, 2021

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.