XML External Entity Vulnerability in Mule Runtime by Salesforce
CVE-2021-1630

7.5HIGH

Key Information:

Vendor

Salesforce

Status
Vendor
CVE Published:
5 August 2021

What is CVE-2021-1630?

This vulnerability pertains to an XML external entity (XXE) issue within specific versions of Salesforce's Mule runtime components. It poses risks for various deployment environments, including CloudHub and on-premise options. Attackers might leverage this vulnerability to gain unintended access to system files or services, potentially leading to sensitive information exposure.

Affected Version(s)

Mulesoft MuleSoft Mule CE/EE 3.x and 4.x released before June 8, 2021

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-1630 : XML External Entity Vulnerability in Mule Runtime by Salesforce