CVE-2022-40705
Summary
| CVE | CVE-2022-40705 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-22 09:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | ** UNSUPPORTED WHEN ASSIGNED ** An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Simple Object Access Protocol | All | All | All | All |
| Application | Apache | Soap | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/02yo04w93rdjmllz4454lvodn5xzhwhl | MISC | lists.apache.org | |
| oss-security - CVE-2022-40705: Apache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTP | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache would like to thank TsungShu Chiu (CHT Security) for reporting this issue
There are currently no legacy QID mappings associated with this CVE.