mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
793 B
Markdown
18 lines
793 B
Markdown
### [CVE-2013-6440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6440)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.oracle.com/security-alerts/cpujan2022.html
|
|
|
|
#### Github
|
|
- https://github.com/auditt7708/rhsecapi
|
|
|