5.3
CVSSv3

CVE-2021-41042

Published: 07/07/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an malicious user to cause an external DTD to be retrieved.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse lyo

Github Repositories

Eclipse Lyo, a Java SDK for OSLC-based tool integration

Eclipse Lyo Introduction The Eclipse Lyo project is focused on providing an SDK to enable adoption of OSLC specifications OSLC (Open Services for Lifecycle Collaboration) is an open community dedicated to reducing barriers for lifecycle tool integration The community authors specifications for exposing lifecycle artifacts through uniform (REST) interfaces and relying on