OSV 1.4.0 · github-reviewed · 修改于 2021-02-25 03:40
发布时间
2021-02-25 03:40
GitHub 审查时间
2019-05-30 03:15
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/02/GHSA-c8m9-mh38-97p9/GHSA-c8m9-mh38-97p9.json
该公告已于 2021-02-25 03:40 撤回
内容仅用于保留外部引用,请不要将其当作仍然有效的安全结论。
An XML eXternal Entity (XXE) Injection was discovered in pmml-model before version 1.4.3. A remote attacker can exploit this vulnerability by sending a request to submit malicious External Entity references within the embedded XML metadata to the target system.