Obdasystems develops Mastro, a specialized application focused on XML processing and data transformation, where the observed vulnerability pattern centers on XML external entity expansion and XXE-related input validation weaknesses. These weakness classes reflect the inherent parsing complexity of XML handling and the need for strict entity reference restriction in untrusted document processing; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Obdasystems over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40511HIGH OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service. | Jun 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-40510HIGH XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs. | Jun 21, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Obdasystems.
Media articles that mention a CVE ID that affects a product developed by Obdasystems — matched by CVE ID, not by vendor name.