Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgq9-fc3q-vqmw

Опубликовано: 25 окт. 2023
Источник: github
Github: Прошло ревью

Описание

Withdrawn Advisory: dom4j XML Entity Expansion vulnerability

Withdrawn Advisory

This advisory has been withdrawn because the underlying vulnerability could not be reproduced. This link is maintained to preserve external references.

Original Description

An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function.

Пакеты

Наименование

org.dom4j:dom4j

maven
Затронутые версииВерсия исправления

<= 2.1.4

Отсутствует

Дефекты

CWE-776

Связанные уязвимости

ubuntu
больше 2 лет назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

redhat
больше 2 лет назад

An issue was found in org.dom4j that may allow a remote attacker to obtain sensitive information via the setFeature function. This CVE is currently disputed by the maintainers.

nvd
больше 2 лет назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Дефекты

CWE-776