ZeroHour

CVE-2021-3541

CVSS 3.1
6.5 medium
EPSS
2%p79
Published
()
Modified
Description

A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

Vendors
xmlsoftredhatoraclenetapp
Products
libxml2, jboss core services, zfs storage appliance kit, active iq unified manager, cloud backup, clustered data ontap, clustered data ontap antivirus connector, manageability software development kit, ontap select deploy administration utility, smi-s provider, snapdrive, h410c firmware
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.