Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10683

Опубликовано: 01 мая 2020
Источник: debian

Описание

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dom4jfixed2.1.3-1package
dom4jno-dsabusterpackage
dom4jno-dsastretchpackage

Примечания

  • https://github.com/dom4j/dom4j/commit/1707bf3d898a8ada3b213acb0e3b38f16eaae73d (the fix?)

  • https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658 (post-fix refactor?)

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS3: 7.4
redhat
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS3: 9.8
nvd
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

suse-cvrf
больше 5 лет назад

Security update for dom4j

CVSS3: 9.8
github
больше 5 лет назад

dom4j allows External Entities by default which might enable XXE attacks