Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqfv-jrvq-95jm

Опубликовано: 09 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP.

This issue affects Apache XML Graphics FOP: 2.9.

Users are recommended to upgrade to version 2.10, which fixes the issue.

Пакеты

Наименование

org.apache.xmlgraphics:fop-core

maven
Затронутые версииВерсия исправления

<= 2.9

2.10

EPSS

Процентиль: 24%
0.00078
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
redhat
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
nvd
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

CVSS3: 7.5
debian
8 месяцев назад

Improper Restriction of XML External Entity Reference ('XXE') vulnerab ...

suse-cvrf
7 месяцев назад

Security update for javapackages-tools, xmlgraphics-batik, xmlgraphics-commons, xmlgraphics-fop

EPSS

Процентиль: 24%
0.00078
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-611