Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28168

Опубликовано: 09 окт. 2024
Источник: debian

Описание

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fopfixed1:2.10+dfsg-1~exp0experimentalpackage
fopfixed1:2.10+dfsg-1package
fopno-dsabookwormpackage
foppostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/10/09/1

  • https://issues.apache.org/jira/browse/FOP-3168

  • https://github.com/apache/xmlgraphics-fop/commit/d96ba9a11710d02716b6f4f6107ebfa9ccec7134 (2_10)

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
redhat
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
nvd
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

suse-cvrf
7 месяцев назад

Security update for javapackages-tools, xmlgraphics-batik, xmlgraphics-commons, xmlgraphics-fop

CVSS3: 5.3
github
8 месяцев назад

Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability