漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Wildfly Xerces 输入验证错误漏洞
Vulnerability Description
Wildfly Xerces是Red hat的一个组件 Wildfly中的Xerces存在安全漏洞,该漏洞允许通过构造恶意的XML文件在某些情况下操作验证过程。
CVSS Information
N/A
Vulnerability Type
N/A