GHSA-g6wm-2v64-wq36
MODERATECVE-2025-27136The LocalS3 service's bucket creation endpoint is vulnerable to XML External Entity (XXE) injection. When processing the CreateBucketConfiguration XML document during bucket creation, the service's XML parser is configured to resolve external entities. This allows an attacker to declare an external entity that references an internal URL, which the server will then attempt to fetch when parsing the
- Affected
- < 1.21
- Fixed in
- 1.21
- Weakness
- CWE-611
- Published
- 2025-03-10
- Source
- github