CVE-2021-47621: XEE
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
Other sources
ClassGraph could allow a remote attacker to obtain sensitive information, caused by improper handling of XML external entity (XXE) declarations. By using a specially crafted pom.xml file, a remote attacker could exploit this vulnerability to read arbitrary files on the server.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47621?
CVE-2021-47621 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2021-47621?
To fix CVE-2021-47621, upgrade ClassGraph to version 4.8.112 or higher.
What types of attacks can exploit CVE-2021-47621?
CVE-2021-47621 is vulnerable to XML eXternal Entity (XXE) attacks that can lead to information disclosure.
Which software versions are affected by CVE-2021-47621?
CVE-2021-47621 affects ClassGraph versions prior to 4.8.112 and IBM Planning Analytics versions up to 2.1.
Can CVE-2021-47621 affect my application security?
Yes, CVE-2021-47621 can compromise application security by allowing attackers to access sensitive data through crafted XML files.