Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
https://www.silverstripe.org/download/security-releases/ | not applicable vendor advisory |
https://github.com/silverstripe/silverstripe-framework/releases | release notes vendor advisory |
https://www.silverstripe.org/download/security-releases/cve-2021-41559 | release notes vendor advisory |