CRITICAL
Improper Restriction of XML External Entity Reference in hazelcast/hazelcast
Published Mar 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 2.79%
Description
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
Affected products
-
- Version 5.1-BETA-1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hazelcast | Hazelcast/hazelcast | n/a |
|
No data.
Red Hat Fuse 7
hazelcast
Not affected
Red Hat Integration Camel K 1
hazelcast
Not affected
Red Hat JBoss Fuse 6
hazelcast
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | hazelcast | Not affected | n/a |
| Red Hat Integration Camel K 1 | hazelcast | Not affected | n/a |
| Red Hat JBoss Fuse 6 | hazelcast | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No RedHat Products are affected by this vulnerability.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2022-0265 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2063927 Issue Tracking
- https://github.com/advisories/GHSA-99wh-973f-779p Advisory
- https://github.com/hazelcast/hazelcast/commit/4d6b666cd0291abd618c3b95cdbb51aa4208e748 x_refsource_MISCPatchThird Party Advisory
- https://github.com/hazelcast/hazelcast/pull/20407
- https://huntr.dev/bounties/d63972a2-b910-480a-a86b-d1f75d24d563 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0265
- https://www.cve.org/CVERecord?id=CVE-2022-0265
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0265 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2063927 | Issue Tracking | |
| https://github.com/advisories/GHSA-99wh-973f-779p | Advisory | |
| https://github.com/hazelcast/hazelcast/commit/4d6b666cd0291abd618c3b95cdbb51aa4208e748 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/hazelcast/hazelcast/pull/20407 | ||
| https://huntr.dev/bounties/d63972a2-b910-480a-a86b-d1f75d24d563 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0265 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0265 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Mar 3, 2022
Updated Aug 2, 2024
Reserved Jan 17, 2022
Link CVE-2022-0265
CISA Vulnrichment
GHSA-99WH-973F-779P Updated n/a