{"id":"CVE-2017-1000061","details":"xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service","modified":"2026-07-08T11:35:10.112737Z","published":"2017-07-17T13:18:17.923Z","references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3PWHBRWXR3RNPHDSTQI6UWDG5ETOQ7VR/"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2492"},{"type":"FIX","url":"https://github.com/lsh123/xmlsec/issues/43"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lsh123/xmlsec","events":[{"introduced":"0"},{"last_affected":"0dcb578db2c1073460958a1d08fafc379c747c98"}],"database_specific":{"cpe":"cpe:2.3:a:xmlsec_project:xmlsec:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.2.23"}],"source":"CPE_RANGE"}}],"versions":["xmlsec-1_2_23","xmlsec-1_2_22","xmlsec-1_2_21","XMLSEC_MIGRATION_TO_GITHUB","xmlsec-1_2_20","xmlsec-1_2_19","xmlsec-1_2_18","xmlsec-1_2_17","xmlsec-1_2_16","xmlsec-1_2_15","xmlsec-1_2_14","xmlsec-1_2_13","xmlsec-1_2_11","xmlsec-1_2_10","xmlsec-1_2_9","xmlsec-1_2_8","xmlsec-1_2_7","xmlsec-1_2_6","xmlsec-1_2_5","xmlsec-1_2_4","XMLSEC_1_2_X_START","XMLSEC_0_0_X_START","xmlsec-1_2_3","xmlsec-1_2_2","xmlsec-1_2_1","xmlsec-1_2_0","xmlsec-1_1_2","XMLSEC_MSCRYPTO_083103_START","xmlsec-1_1_1","xmlsec-1_1_0","xmlsec-1_0_4","xmlsec-1_0_3","xmlsec-1_0_2","xmlsec-1_0_1","xmlsec-1_0_0","xmlsec-","xmlsec-1_0_0rc1","xmlsec-1_0_0pre1","xmlsec-0_1_1","xmlsec-0_1_0","XMLSEC_0211104","xmlsec-0_0_10","xmlsec-0_0_9","xmlsec-0_0_8a","xmlsec-0_0_8","xmlsec-0_0_7","xmlsec-0_0_5","start"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000061.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}