CVE-2021-23901
Summary
| CVE | CVE-2021-23901 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-25 10:16:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Nutch 1.18. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [announce] 20210124 CVE-2021-23901: An XML external entity (XXE) injection vulnerability exists in the Nutch DmozParser | lists.apache.org | ||
| [nutch-dev] 20210125 Re: CVE-2021-23901: An XML external entity (XXE) injection vulnerability exists in the Nutch DmozParser | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Patch, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | CONFIRM | lists.apache.org | Mailing List, Vendor Advisory |
| CVE-2021-23901 Apache Nutch Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [NUTCH-2841] Upgrade xercesImpl dependency - ASF JIRA | CONFIRM | issues.apache.org | Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: The Apache Nutch Project Management Committee would like to thank Martin Heyden for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.