CVE-2020-15232 Information

Description

In mapfish-print before version 3.24 a user can do to an XML External Entity (XXE) attack with the provided SDL style.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Reference

https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e https://github.com/mapfish/mapfish-print/security/advisories/GHSA-vjv6-gq77-3mjw

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

HIGH

Base Severity

9.1

Share on: