{"id":"GHSA-g6v7-vqhx-6v6c","summary":"XML External Entity Reference in org.opencms:opencms-core","details":"An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.","aliases":["CVE-2021-3312"],"modified":"2023-11-08T04:06:03.398566Z","published":"2021-10-12T17:23:40Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-10-11T18:55:10Z","nvd_published_at":"2021-10-08T15:15:00Z","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3312"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/issues/721"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/issues/725"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/commit/92e035423aa6967822d343e54392d4291648c0ee"},{"type":"PACKAGE","url":"https://github.com/alkacon/opencms-core"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/releases"}],"affected":[{"package":{"name":"org.opencms:opencms-core","ecosystem":"Maven","purl":"pkg:maven/org.opencms/opencms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"12.0.0"}]}],"versions":["11.0.0","11.0.1","11.0.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 11.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-g6v7-vqhx-6v6c/GHSA-g6v7-vqhx-6v6c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}