XML External Entity Vulnerability in Eclipse Lyo Software
CVE-2021-41042
5.3MEDIUM
What is CVE-2021-41042?
Eclipse Lyo versions 1.0.0 to 4.1.0 contain a vulnerability where the TransformerFactory is set up with default configurations allowing unrestricted DTD loading while processing RDF/XML. This flaw can be exploited by attackers to retrieve external DTDs, potentially leading to unauthorized data access or manipulation.
Affected Version(s)
Eclipse Lyo 1.0.0
Eclipse Lyo <= 4.1.0
