CVE-2015-3160

Publication date

2017-09-06 21:00:00

Family

redhat

State

PUBLISHED

Description

XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker servers file system.