
Cloud Vulnerability DB
A community-led vulnerabilities database
An XML External Entity (XXE) vulnerability was discovered in the MuleSoft APIkit project on March 25, 2020, identified as CVE-2020-10991. The vulnerability was found in the RestXmlSchemaValidator.java file within the project's codebase (GitHub Issue).
The vulnerability exists in the RestXmlSchemaValidator.java file (lines 150-158) where the DocumentBuilderFactory is instantiated without proper XXE protection settings. The code sets up XML parsing with namespace awareness enabled but fails to implement necessary security controls to prevent XXE attacks (GitHub Issue).
XML External Entity (XXE) vulnerabilities can allow attackers to disclose internal files, perform server-side request forgery, or execute denial of service attacks through the parsing of malicious XML input (OWASP).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."