Описание
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libpdfbox2-java | not-affected | package | ||
| libpdfbox-java | not-affected | package |
Примечания
https://www.openwall.com/lists/oss-security/2019/04/12/1
https://issues.apache.org/jira/browse/PDFBOX-4505
Fixed by: https://svn.apache.org/r1856952 (2.0.15)
EPSS
Связанные уязвимости
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Vulnerability that affects org.apache.pdfbox:pdfbox
Уязвимость синтаксического анализатора XML Java-библиотеки Apache PDFBox, позволяющая нарушителю проводить XXE-атаки
EPSS