"-Synchronized-Data."

This commit is contained in:
CVE Team 2022-08-16 11:00:39 +00:00
parent 752b5bb418
commit 46bf0c9828
No known key found for this signature in database
GPG Key ID: E3252B3D49582C98

View File

@ -4,7 +4,7 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2022-2838",
"ASSIGNER": "cve@mitre.org",
"ASSIGNER": "security@eclipse.org",
"STATE": "PUBLIC"
},
"affects": {
@ -39,7 +39,7 @@
"description_data": [
{
"lang": "eng",
"value": "In Eclipse Sphinx before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests."
"value": "In Eclipse Sphinx\u2122 before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests."
}
]
},