CVE-2022-2414
Summary
| CVE | CVE-2022-2414 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-29 19:15:00 UTC |
| Updated | 2022-08-04 20:25:00 UTC |
| Description | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Disable access to external entities when parsing XML by ckelleyRH · Pull Request #4021 · dogtagpki/pki · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160198 Oracle Enterprise Linux Security Update for pki-core (ELSA-2022-7326)
- 160225 Oracle Enterprise Linux Security Update for pki-core:10.6 and pki-deps:10.6 (ELSA-2022-7470)
- 160344 Oracle Enterprise Linux Security Update for pki-core (ELSA-2022-8799)
- 240806 Red Hat Update for pki-core (RHSA-2022:7326)
- 240845 Red Hat Update for pki-core:10.6 and pki-deps:10.6 (RHSA-2022:7470)
- 240964 Red Hat Update for pki-core (RHSA-2022:8799)
- 241378 Red Hat Update for pki-core:10.6 (RHSA-2023:1966)
- 241564 Red Hat Update for pki-core:10.6 (RHSA-2023:3394)
- 241675 Red Hat Update for pki-core:10.6 (RHSA-2023:1747)
- 257217 CentOS Security Update for pki-core (CESA-2022:8799)
- 354895 Amazon Linux Security Advisory for pki-core : ALAS2-2023-2016
- 377787 Alibaba Cloud Linux Security Update for pki-core:10.6 and pki-deps:10.6 (ALINUX3-SA-2022:0184)
- 377849 Alibaba Cloud Linux Security Update for pki-core (ALINUX2-SA-2022:0057)
- 673071 EulerOS Security Update for pki-core (EulerOS-SA-2023-2164)
- 673078 EulerOS Security Update for pki-core (EulerOS-SA-2023-2197)
- 940725 AlmaLinux Security Update for pki-core (ALSA-2022:7326)
- 940764 AlmaLinux Security Update for pki-core:10.6 and pki-deps:10.6 (ALSA-2022:7470)
- 960545 Rocky Linux Security Update for pki-core:10.6 and pki-deps:10.6 (RLSA-2022:7470)
- 960564 Rocky Linux Security Update for pki-core (RLSA-2022:7326)