vendor:
Apache Olingo OData 4.0
by:
Archibald Haddock
5.5
CVSS
MEDIUM
XML External Entity Resolution (XXE)
611
CWE
Product Name: Apache Olingo OData 4.0
Affected Version From: Olingo OData 4.x.x
Affected Version To: Olingo OData 4.6.x
Patch Exists: YES
Related CWE: CVE-2019-17554
CPE: a:apache:olingo_odata:4.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Apache Olingo OData 4.0 XML External Entity Resolution (XXE)
The XML content type entity deserializer is not configured to deny the resolution of external entities. Request with content type 'application/xml', which trigger the deserialization of entities, can be used to trigger XXE attacks.
Mitigation:
Upgrade to Olingo OData 4.7.0 or later versions.