XXE through inventory file facilitates file disclosure
Package
rudder-server
(rudder)
Affected versions
< 8.1.6
Patched versions
8.1.6
rudder-webapp
(rudder)
*
None
Impact
A forged inventory can lead to requesting a malicious external entity when parsing inventory:
Patches
Workarounds
None.
References