{"id":"CVE-2021-47621","aliases":["GHSA-v2xm-76pq-phcf"],"url":"https://o3.security/vulnerability/CVE-2021-47621","summary":"ClassGraph XML External Entity Reference","details":"ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.","published":"2024-06-21T06:15:10.487Z","modified":"2026-07-09T03:25:20.171719Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.github.classgraph:classgraph","fixedVersion":"4.8.112"}],"fix":{"url":"https://github.com/classgraph/classgraph/commit/681362ad6b0b9d9abaffb2e07099ce54d7a41fa3","label":"classgraph/classgraph@681362a"},"references":[{"type":"WEB","url":"https://docs.r3.com/en/platform/corda/4.8/enterprise/release-notes-enterprise.html"},{"type":"WEB","url":"https://github.com/classgraph/classgraph/releases/tag/classgraph-4.8.112"},{"type":"FIX","url":"https://github.com/classgraph/classgraph/commit/681362ad6b0b9d9abaffb2e07099ce54d7a41fa3"},{"type":"FIX","url":"https://github.com/classgraph/classgraph/pull/539"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T03:25:20.171719Z"}}