XML external entity (XXE) vulnerability
High severity
GitHub Reviewed
Published
Feb 24, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Feb 24, 2021
Description
Reviewed
May 29, 2019
Published to the GitHub Advisory Database
Feb 24, 2021
Withdrawn
Feb 24, 2021
Last updated
Jan 9, 2023
An XML eXternal Entity (XXE) Injection was discovered in pmml-model before version 1.4.3. A remote attacker can exploit this vulnerability by sending a request to submit malicious External Entity references within the embedded XML metadata to the target system.
References