Apache Cocoon vulnerabilities

4 known vulnerabilities affecting apache/cocoon.

Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-45135CRITICALCVSS 9.8≥ 2.2.0, < 2.3.02023-11-30
CVE-2022-45135 [CRITICAL] CWE-89 CVE-2022-45135: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
nvd
CVE-2023-49733CRITICALCVSS 9.8≥ 2.2.0, < 2.3.02023-11-30
CVE-2023-49733 [CRITICAL] CWE-611 CVE-2023-49733: Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affe Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
nvd
CVE-2020-11991HIGHCVSS 7.5PoC≥ 2.1, ≤ 2.1.122020-09-11
CVE-2020-11991 [HIGH] CWE-611 CVE-2020-11991: When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, includi When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
nvd
CVE-2003-1172MEDIUMCVSS 5.0PoCv2.1v2.1.2+1 more2003-12-31
CVE-2003-1172 [MEDIUM] CVE-2003-1172: Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoo Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
nvd
Apache Cocoon vulnerabilities | cvebase