CVE Database
/

CVE-2019-1010268

Back to search

CVE-2019-1010268

Published: Jul 18, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance: https://bitbucket.org/jakobsg/ladon/src/42944fc012a3a48214791c120ee5619434505067/src/ladon/interfaces/soap.py#lines-688. The attack vector is: Send a specially crafted SOAP call.

VendorProductVersions

Ladon

Ladon

affected
0.9.40 and previous (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now