VDB
Sign up
HIGH

GHSA-qm4x-ch5w-gr62

XXE in SabreDAV

Quick fix

GHSA-qm4x-ch5w-gr62 — sabre/dav: upgrade to the fixed version with the command below.

composer require sabre/dav:^1.7.11

Details

SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sabre/dav
Introduced in: 1.6.0Fixed in: 1.7.11
Fixcomposer require sabre/dav:^1.7.11
Packagist/sabre/dav
Introduced in: 1.8.0Fixed in: 1.8.9
Fixcomposer require sabre/dav:^1.8.9

References