An attacker with access to an HX 10.0.0 and previous...
Moderate severity
Unreviewed
Published
Jan 29, 2025
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Jan 29, 2025
Published to the GitHub Advisory Database
Jan 29, 2025
Last updated
Jan 29, 2025
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.
References