Due to missing validation of XML input, an...
Moderate severity
Unreviewed
Published
Dec 10, 2024
to the GitHub Advisory Database
•
Updated Dec 10, 2024
Description
Published by the National Vulnerability Database
Dec 10, 2024
Published to the GitHub Advisory Database
Dec 10, 2024
Last updated
Dec 10, 2024
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
References