[Japanese] | |
JVNDB-2024-000010 | |
Improper restriction of XML external entity references (XXE) in "Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version)" | |
Overview | |
"Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version)" provided by Ministry of Agriculture, Forestry and Fisheries improperly restricts XML external entity references (XXE) (CWE-611). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 2.5 (Low) [IPA Score]
CVSS V2 Severity:
Base Metrics 1.2 (Low) [IPA Score]
| |
Affected Products | |
| |
Ministry of Agriculture, Forestry and Fisheries | |
| |
Impact | |
Processing a specially crafted XML file may lead to exposure of internal files on the system. | |
Solution | |
[Update the Software] | |
Vendor Information | |
Ministry of Agriculture, Forestry and Fisheries | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/01/23 |
Date First Published | 2024/01/23 |
Date Last Updated | 2024/03/14 |