Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18197

Опубликовано: 24 фев. 2018
Источник: debian
EPSS Низкий

Описание

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjgraphx-javafixed2.1.0.7-2package
libjgraphx-javano-dsastretchpackage
libjgraphx-javano-dsajessiepackage

Примечания

  • https://github.com/jgraph/mxgraph/issues/124

  • https://bitbucket.org/jgraph/mxgraph2/commits/7d159ca3259b961cbb1c51b4ea42cb408c624ff1

EPSS

Процентиль: 63%
0.0044
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

CVSS3: 4.8
redhat
около 8 лет назад

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

CVSS3: 9.8
nvd
почти 8 лет назад

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

suse-cvrf
почти 8 лет назад

Security update for jgraphx

CVSS3: 9.8
github
больше 3 лет назад

mxGraph vulnerable to XXE attacks

EPSS

Процентиль: 63%
0.0044
Низкий