Vulnerability Description
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
CVSS Score
5.9
MEDIUM
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grails | Pdf Plugin | 0.6 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96446Third Party AdvisoryVDB Entry
- https://www.ambionics.io/blog/grails-pdf-plugin-xxeExploitThird Party Advisory
- http://www.securityfocus.com/bid/96446Third Party AdvisoryVDB Entry
- https://www.ambionics.io/blog/grails-pdf-plugin-xxeExploitThird Party Advisory
FAQ
What is CVE-2017-6344?
CVE-2017-6344 is a vulnerability with a CVSS score of 5.9 (MEDIUM). XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
How severe is CVE-2017-6344?
CVE-2017-6344 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6344?
Check the references section above for vendor advisories and patch information. Affected products include: Grails Pdf Plugin.