CVE-2022-34716XML External Entity (XXE) Injection in Microsoft Microsoft.aspnetcore.app.runtime.linux-arm

Severity
5.9MEDIUM
No vector
EPSS
1.0%
top 23.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateFeb 3

Description

dotnet: External Entity Injection during XML signature verification .NET Spoofing Vulnerability An information disclosure vulnerability exists in .NET Core and .NET. This issue can lead to unauthorized access to privileged information.

Affected Packages12 packages

🔴Vulnerability Details

2
OSV
.NET Information Disclosure Vulnerability2024-02-03
GHSA
.NET Information Disclosure Vulnerability2024-02-03

📋Vendor Advisories

2
Red Hat
dotnet: External Entity Injection during XML signature verification2022-08-09
Microsoft
.NET Spoofing Vulnerability2022-08-09
CVE-2022-34716 — XML External Entity (XXE) Injection | cvebase