CVE-2024-49340
High (8.9)
A vulnerability in woodstox-core allows attackers to exploit XML External Entity (XXE) processing to make unauthorized requests to internal network resources or read local files during XML parsing operations. The flaw exists in the XML parser's handling of external entity references, which can be triggered by processing maliciously crafted XML input. Applications that parse untrusted XML using affected versions of woodstox-core are at risk of server-side request forgery (SSRF) or local file disclosure.
- Reserved
- Oct 15, 2024
- Published
- Oct 24, 2024
- Modified
- Nov 5, 2024
CVSS Assessment
Source: CVE project
Version 3.1
Current
High (8.9)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
| Version | Status | Supplier | |||
|---|---|---|---|---|---|
| ach-processor-9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 | 9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 |
Affected | 118 | Lightwell | Aug 17, 2026 |
| benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781 | 9b416d7055d8de529f2255ff2b1db1ca22bc5781 |
Affected | 92 | Lightwell | Aug 17, 2026 |
1 - 2 of 2
| ID | Title | Type | Revision | Vulnerabilities |
|---|---|---|---|---|
| CVE-2024-49340 | woodstox-core: XML External Entity processing allows unauthorized resource access | cve | Nov 5, 2024 | 1 |
| GHSA-fhf9-wk7p-dfgq | osv | Oct 24, 2024 | 1 |
1 - 2 of 2