Vulnerability Details CVE-2022-27193
CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 48.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2022-27193
-
cpe:2.3:a:cvrf-csaf-converter_project:cvrf-csaf-converter:1.0.0