Security Advisory

CVE-2021-42560

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-01-12 18:58:06
Last updated 2024-08-04 03:38:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).