An XML external entity (XXE) injection vulnerability exists in Apache Any23 StreamUtils.java
CVE-2021-38555

9.1CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
11 September 2021

Summary

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.

Affected Version(s)

Apache Any23 Apache Any23 < 2.5

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Any23 Project Management Committee would like to thank Zhuxuan Wu for reporting the security vulnerability.
.