Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j69f-fgh5-f7mc

Опубликовано: 30 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

iText RUPS XML External Entity vulnerability

A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The name of the patch is ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.

Пакеты

Наименование

com.itextpdf:itext-rups

maven
Затронутые версииВерсия исправления

<= 7.0.1

Отсутствует

EPSS

Процентиль: 53%
0.00307
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch is identified as ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.

CVSS3: 5.5
nvd
около 3 лет назад

A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch is identified as ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 53%
0.00307
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611