The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
References
Configurations
History
No history.
Information
Published : 2023-06-05 04:15
Updated : 2023-06-13 13:15
NVD link : CVE-2023-34411
Mitre link : CVE-2023-34411
CVE.ORG link : CVE-2023-34411
JSON object : View
Products Affected
xml_library_project
- xml_library
CWE
CWE-611
Improper Restriction of XML External Entity Reference