BlueCat Device Registration Portal 2.2 allows XXE attacks...
High severity
Unreviewed
Published
Jan 15, 2023
to the GitHub Advisory Database
•
Updated Jan 24, 2023
Description
Published by the National Vulnerability Database
Jan 15, 2023
Published to the GitHub Advisory Database
Jan 15, 2023
Last updated
Jan 24, 2023
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE; 2.x versions are no longer supported. There is no available information about whether any later version is affected.
References