Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v35-qwwj-p98g

Опубликовано: 05 июл. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Restriction of XML External Entity Reference in DiffPlug Spotless

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

Пакеты

Наименование

com.diffplug.spotless:spotless-plugin-gradle

maven
Затронутые версииВерсия исправления

< 3.20.0

3.20.0

Наименование

com.diffplug.spotless:spotless-maven-plugin

maven
Затронутые версииВерсия исправления

< 1.20.0

1.20.0

EPSS

Процентиль: 56%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

EPSS

Процентиль: 56%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-611