1 results (0.006 seconds)

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. Se ha encontrado un fallo en vscode-xml en las versiones anteriores a 0.19.0. La descarga de esquemas podría conllevar a una vulnerabilidad de tipo SSRF ciego o un DoS por medio de un archivo grande • https://github.com/eclipse/lemminx/blob/master/CHANGELOG.md#0190-february-14-2022 https://github.com/redhat-developer/vscode-xml/blob/master/CHANGELOG.md#0190-february-14-2022 • CWE-400: Uncontrolled Resource Consumption CWE-918: Server-Side Request Forgery (SSRF) •