CVE Database
/

CVE-2022-2838

Back to search

CVE-2022-2838

Published: Aug 16, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

VendorProductVersions

The Eclipse Foundation

Eclipse Sphinx

affected
0.7.0 - < unspecified
affected
unspecified - < 0.13.1

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now