Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted XML file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Stroom XML解析器安全漏洞
Vulnerability Description
Stroom是一套可扩展的数据存储、处理和分析平台。 Stroom 5.4.5之前版本中的XML解析器存在XML外部实体注入漏洞。攻击者可借助特制的XML文件利用该漏洞泄露敏感信息,造成拒绝服务,伪造服务器端请求或扫描端口。
CVSS Information
N/A
Vulnerability Type
N/A