NFLX-2015-001
External Entity Injection (XXE) in recipes-rss open-source application
Scott Behrens / [email protected]
02/22/2015
recipes-rss
https://github.com/Netflix/recipes-rss
High
An XML external entity injection (XXE) vulnerability was discovered in the Netflix recipes-rss open-source application. An attacker that exploits this attack may use it to read arbitrary files or AWS meta-data from the underlying web server.