XML External Entity (XXE) Injection Affecting prosody package, versions <0.11.12-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.13% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about XML External Entity (XXE) Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-ALPINE318-PROSODY-5516678
  • published14 Jan 2022
  • disclosed26 Aug 2022

Introduced: 14 Jan 2022

CVE-2022-0217  (opens in a new tab)
CWE-611  (opens in a new tab)
CWE-776  (opens in a new tab)

How to fix?

Upgrade Alpine:3.18 prosody to version 0.11.12-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream prosody package and not the prosody package as distributed by Alpine. See How to fix? for Alpine:3.18 relevant fixed versions and status.

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

CVSS Scores

version 3.1