HIGH
GHSA-qm4x-ch5w-gr62
XXE in SabreDAV
Quick fix
GHSA-qm4x-ch5w-gr62 — sabre/dav: upgrade to the fixed version with the command below.
composer require sabre/dav:^1.7.11Details
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-2055[ADVISORY]
- https://github.com/sabre-io/dav/issues/414[WEB]
- https://github.com/sabre-io/dav/commit/e3f46e0ecf83cf1d2ebf54908cde7b5ec170aa2c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/sabre/dav/CVE-2014-2055.yaml[WEB]
- https://github.com/fruux/sabre-dav/releases/tag/1.7.11[WEB]