CVE Vulnerabilities

CVE-2022-21949

Improper Restriction of XML External Entity Reference

Published: May 03, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the server that can be abused to escalate to Admin privileges on OBS. This issue affects: SUSE Open Build Service Open Build Service versions prior to 2.10.13.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Open_build_service Opensuse * 2.10.13 (excluding)
Ruby-xmlhash Ubuntu bionic *
Ruby-xmlhash Ubuntu focal *
Ruby-xmlhash Ubuntu impish *
Ruby-xmlhash Ubuntu kinetic *
Ruby-xmlhash Ubuntu lunar *
Ruby-xmlhash Ubuntu mantic *
Ruby-xmlhash Ubuntu oracular *

Potential Mitigations

References