« Volver al listado

CVE-2022-2414

Estado: ModificadaAlta (7.5)—

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2414",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Dogtag PKI",
          "versions": [
            {
              "status": "affected",
              "version": "Affected versions: 10.5.18, 10.7.4, 10.8.3, 10.11.2, 10.12.4, 11.0.5, 11.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-29T19:15:08.477",
  "references": [
    {
      "url": "https://github.com/dogtagpki/pki/pull/4021",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/dogtagpki/pki/pull/4021",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests."
    },
    {
      "lang": "es",
      "value": "El acceso a entidades externas cuando son analizados documentos XML puede conllevar a ataques de tipo XML external entity (XXE). Este fallo permite a un atacante remoto recuperar potencialmente el contenido de archivos arbitrarios mediante el envío de peticiones HTTP especialmente diseñadas"
    }
  ],
  "lastModified": "2026-06-17T04:41:51.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:10.5.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "710A4771-7E37-4FD6-9A49-1E2BBAA8C201"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:10.7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F10F73EF-D53F-4D8B-9199-E383B8274E8B"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:10.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE671D4C-D0F5-41E0-AE41-4F512B717439"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:10.11.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C84F9BCF-B6FF-48BB-99A0-EC93437EF903"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:10.12.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "223FB53B-E8F9-44D8-9DE3-D9F58E7FFACE"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:11.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F884A4B-D433-4492-9E98-8E3B06EA92DB"
            },
            {
              "criteria": "cpe:2.3:a:dogtagpki:dogtagpki:11.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "606FEDCA-EA05-45F9-938D-067723F1FFEE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}