CVE Vulnerabilities

CVE-2014-5392

Published: Sep 23, 2014 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.

Affected Software

Name Vendor Start Version End Version
Jobscheduler Sos 1.6.4043 1.6.4043
Jobscheduler Sos 1.7.4189 1.7.4189
Jobscheduler Sos 1.6.4014 1.6.4014
Jobscheduler Sos 1.7.4177 1.7.4177
Jobscheduler Sos * 1.6.4131

References