CVE-2022-0198 Information

Description

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Reference

https://github.com/stanfordnlp/corenlp/commit/1f52136321cfca68b991bd7870563d06cf96624d https://huntr.dev/bounties/3d7e70fe-dddd-4b79-af62-8e058c4d5763

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.1

Share on: