CVE-2024-55875 - "HTTP4K XML External Entity Injection (XXE) Vulnerability"

CVE ID : CVE-2024-55875 Published : Dec. 12, 2024, 7:15 p.m. | 2 hours, 44 minutes ago Description : http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 contains a patch for the issue. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Dez 12, 2024 - 23:00
 0  2
CVE-2024-55875 - "HTTP4K XML External Entity Injection (XXE) Vulnerability"
CVE ID : CVE-2024-55875
Published : Dec. 12, 2024, 7:15 p.m. | 2 hours, 44 minutes ago
Description : http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 contains a patch for the issue.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...