cve/2021/CVE-2021-27736.md
2024-05-25 21:48:12 +02:00

690 B

CVE-2021-27736

Description

FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.

POC

Reference

No PoCs from references.

Github