← Vulnerability feed

Vulnerability record · CVE-2022-2414 · published 29 July 2022

CVE-2022-2414: Dogtag PKI XML parser allows XXE file disclosure

Dogtagpki · Dogtagpki

Dogtag PKI parses XML documents with external entity resolution enabled, exposing it to XML external entity (XXE) attacks. A remote attacker can send a crafted HTTP request to read arbitrary files from the server. The flaw is rated CVSS 7.5 (HIGH) with confidentiality impact only.

7.5 CVSS 3.1 High EPSS 86% · top 0.3% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.5 with no authentication or interaction required and a very high EPSS score, though no KEV listing or known exploit reference.

What it is

Dogtag PKI parses XML documents with external entity resolution enabled, exposing it to XML external entity (XXE) attacks. A remote attacker can send a crafted HTTP request to read arbitrary files from the server. The flaw is rated CVSS 7.5 (HIGH) with confidentiality impact only.

Impact

An attacker gains read access to arbitrary files on the host, which can expose credentials, configuration and key material. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to the XML-parsing endpoint; the vector shows no privileges (PR:N) and no user interaction (UI:N) required.

Exploitation

Not listed in CISA KEV and no public exploit reference is provided, but EPSS is very high (0.856, 99.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the patch referenced in dogtagpki/pki pull request 4021 and upgrade to a fixed release.
  • Disable external entity and DTD processing in the XML parser used by the PKI service.
  • Restrict network access to the affected HTTP endpoints to trusted clients only.
  • Run the PKI service with least privilege and limit readable filesystem paths.
  • Monitor for anomalous outbound requests or file-read patterns from the PKI host.

Detection

  • Inspect HTTP request bodies to XML endpoints for DOCTYPE, ENTITY or SYSTEM/PUBLIC declarations.
  • Alert on XML parser errors or unexpected file-read activity by the PKI process.
  • Review server logs for requests containing external entity payloads or unusual parameter values.
  • Baseline and monitor file access by the PKI service account for reads outside expected paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/dogtagpki/pki/pull/4021 Issue TrackingPatchThird Party Advisory
https://github.com/dogtagpki/pki/pull/4021 Issue TrackingPatchThird Party Advisory

Track CVE-2022-2414 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-20179Dogtagpki incorrect authorization vulnerabilityA flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …EPSS 1.2%8.1CVE-2018-1080Dogtagpki improper access control vulnerabilityDogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and…EPSS 1.5%7.8CVE-2021-3551Dogtagpki cleartext storage of sensitive data vulnerabilityA flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This …EPSS 0.19%7.5CVE-2017-7537Redhat enterprise linux desktop hard-coded credentials vulnerabilityIt was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.…EPSS 1.5%6.8CVE-2020-15720Dogtagpki improper certificate validation vulnerabilityIn Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter wa…EPSS 1.0%6.1CVE-2020-25715Dogtagpki cross-site scripting vulnerabilityA flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject …EPSS 1.1%6.1CVE-2020-1721Dogtagpki cross-site scripting vulnerabilityA flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a ke…EPSS 0.98%6.1CVE-2019-10179Redhat enterprise linux cross-site scripting vulnerabilityA vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery re…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2022-2414), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.