The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xmltooling | Mar 13, 2019 | Mar 13, 2019 |
| Suse | — | Upgrade libxmltooling-lite9Upgrade libxmltooling9Upgrade libxmltooling7Upgrade xmltooling-schemasUpgrade libxmltooling6Upgrade libxmltooling-devel | Apr 11, 2019 | Mar 26, 2019 |
| Ubuntu | — | Upgrade libxmltooling8Upgrade libxmltooling6Upgrade libxmltooling7Upgrade libxmltooling6v5 | Apr 3, 2019 | Mar 26, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub