CVE-2022-40152
medium · 6.5Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
6.5
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2022-09-16
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-121CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| xstream | xstream | < 1.4.20 |
| fasterxml | woodstox | < 5.4.0 |
| fasterxml | woodstox | >= 6.0.0, < 6.4.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-40152