CVE-2023-49733: Apache Cocoon
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
Affected products
- Apache Cocoon: from 2.2.0, before 2.3.0 (fixed in 2.3.0)
Published 2023-11-30. Last modified 2026-06-17.