VULNERABILITY INTELLIGENCE
CVE-2012-1102
CVSS score7.5 HIGH
EPSS probability1.40%
CISA KEVNot currently listed
Published2021-07-09
Last modified2026-06-16
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
Weakness classification
- CWE-611: Improper Restriction of XML External Entity Reference
Primary references
- secalert@redhat.com — Release Notes, Third Party Advisory
- secalert@redhat.com — Exploit, Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Release Notes, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Mailing List, Third Party Advisory