The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml-libxml-perl | Jul 30, 2024 | May 12, 2015 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | May 12, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 23, 2015 |
| Suse | — | Upgrade perl-XML-LibXML | Dec 18, 2015 | May 12, 2015 |
| Ubuntu | — | Upgrade libxml-libxml-perl | Nov 8, 2024 | May 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub