ZeroHour

CVE-2019-7722

PoC
CVSS 3.0
8.1 high
EPSS
1%p67
Published
()
Modified
Description

PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or request forgery attacks. (PMD 6.x is unaffected because of a 2017-09-15 change.)

Vendors
pmd project
Products
pmd
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.