Описание
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
libjdom2-intellij-java | unfixed | package | ||
libjdom2-intellij-java | ignored | trixie | package | |
libjdom2-intellij-java | ignored | bookworm | package | |
libjdom2-intellij-java | no-dsa | bullseye | package | |
libjdom2-intellij-java | no-dsa | buster | package | |
libjdom2-java | fixed | 2.0.6-2.1 | package | |
libjdom2-java | no-dsa | buster | package | |
libjdom1-java | fixed | 1.1.3-2.1 | package | |
libjdom1-java | no-dsa | buster | package |
Примечания
https://github.com/hunterhacker/jdom/pull/188
https://alephsecurity.com/vulns/aleph-2021003
Fixed by: https://github.com/hunterhacker/jdom/commit/bd3ab78370098491911d7fe9d7a43b97144a234e
Possible regression impact: https://github.com/hunterhacker/jdom/pull/188#issuecomment-872685011
Improved regression with: https://github.com/hunterhacker/jdom/commit/dd4f3c2fc7893edd914954c73eb577f925a7d361
https://github.com/hunterhacker/jdom/commit/07f316957b59d305f04c7bdb26292852bcbc2eb5
Связанные уязвимости
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.