CVE-2021-41411
published 2022-06-16CVE-2021-41411: drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.19%
64.5th percentile
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | drools | < 7.6.0 | 7.6.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Rulesets (XStream) — CVE-2021-41411
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2021-41411 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Rulesets (XStream) — CVE-2021-41411
Oracle Oracle Communications Applications Risk Matrix: Rulesets (XStream) vulnerability
CVE: CVE-2021-41411
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
drools-compiler: XML External Entity vulnerability in KieModuleMarshaller.java
vendor_redhat·2021-08-30·CVSS 9.8
CVE-2021-41411 [CRITICAL] CWE-611 drools-compiler: XML External Entity vulnerability in KieModuleMarshaller.java
drools-compiler: XML External Entity vulnerability in KieModuleMarshaller.java
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
A flaw was found in the XML external entity injection vulnerability in the KieModuleMarshaller.java module of drools-compiler. This issue may lead to the disclosure of sensitive information.
Package: business-central.war (Red Hat Process Automation 7) - Not affected
Package: kie-server.war (Red Hat Process Automation 7) - Not affected
OSV
XML External Entity Reference in drools
osv·2022-06-17
CVE-2021-41411 [CRITICAL] XML External Entity Reference in drools
XML External Entity Reference in drools
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
GHSA
XML External Entity Reference in drools
ghsa·2022-06-17
CVE-2021-41411 [CRITICAL] CWE-611 XML External Entity Reference in drools
XML External Entity Reference in drools
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-16
Published