CVE-2020-11991 is a high-severity XML External Entity (XXE) vulnerability affecting Apache Cocoon, specifically when using its StreamGenerator. An unauthenticated attacker can craft a malicious XML input to access arbitrary files on the server, leading to sensitive data disclosure. While there is no evidence of active exploitation or public exploit code like Metasploit or ExploitDB entries, Nuclei templates exist, and its high EPSS score indicates a significant likelihood of future exploitation. Community discussion and media coverage are minimal, which is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1, <= 2.1.12CPE matchmatch criteria | cpe:2.3:a:apache:cocoon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.