Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwj3-m3p6-hj38

Опубликовано: 05 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

dom4j allows External Entities by default which might enable XXE attacks

dom4j before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Note: This advisory applies to dom4j:dom4j version 1.x legacy artifacts. To resolve this a change to the latest version of org.dom4j:dom4j is recommended.

Пакеты

Наименование

org.dom4j:dom4j

maven
Затронутые версииВерсия исправления

< 2.0.3

2.0.3

Наименование

org.dom4j:dom4j

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.3

2.1.3

Наименование

dom4j:dom4j

maven
Затронутые версииВерсия исправления

<= 1.6.1

Отсутствует

EPSS

Процентиль: 85%
0.02332
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS3: 7.4
redhat
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS3: 9.8
nvd
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

CVSS3: 9.8
debian
почти 6 лет назад

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and Ext ...

suse-cvrf
больше 5 лет назад

Security update for dom4j

EPSS

Процентиль: 85%
0.02332
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611