HIGH
Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp
Published Jan 13, 2022
7.1
HIGHCVSS 3.1
EPSS 0.74%
Description
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
Affected products
-
- Version unspecifiedStatusaffectedConstraints<4.3.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Stanfordnlp | Stanfordnlp/corenlp | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-mh83-jcw5-rjh8 Advisory
- https://github.com/stanfordnlp/corenlp/commit/1f52136321cfca68b991bd7870563d06cf96624d x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/3d7e70fe-dddd-4b79-af62-8e058c4d5763 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0198
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-mh83-jcw5-rjh8 | Advisory | |
| https://github.com/stanfordnlp/corenlp/commit/1f52136321cfca68b991bd7870563d06cf96624d | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/3d7e70fe-dddd-4b79-af62-8e058c4d5763 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0198 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Jan 13, 2022
Updated Aug 2, 2024
Reserved Jan 12, 2022
Link CVE-2022-0198
CISA Vulnrichment
GHSA-MH83-JCW5-RJH8 Updated n/a