Back to Labs
Weakness (CWE)

CWE-611

Improper Restriction of XML External Entity Reference

About

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Common consequences

  • Confidentiality → Read Application Data, Read Files or Directories
  • Integrity → Bypass Protection Mechanism
  • Availability → DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)

Mitigations

  • Implementation, System Configuration: Many XML parsers and validators can be configured to disable external entity expansion.

CVEs with this weakness

Frequently asked questions

What is CWE-611?

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Which platforms does CWE-611 affect?

CWE-611 has been observed on: XML, Not Technology-Specific, Web Based.

How many CVEs does Rainforest track for CWE-611?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-611. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.