Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
drools 代码问题漏洞
Vulnerability Description
drools是KIE开源的一个业务规则管理系统。适用于 Java 和 JVM 平台的开源规则引擎、DMN 引擎和复杂事件处理 (CEP) 引擎。 drools 7.59.x及其之前版本存在安全漏洞,该漏洞源于KieModuleMarshaller.java中Validator类没有正确使用,导致XML外部实体注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A