Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp2f-hrg2-3r5m

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Improper Restriction of XML External Entity Reference in Apache uimaj

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.

Пакеты

Наименование

org.apache.uima:uimafit-core

maven
Затронутые версииВерсия исправления

< 2.4.0

2.4.0

Наименование

org.apache.uima:uimaj-core

maven
Затронутые версииВерсия исправления

< 2.10.2

2.10.2

Наименование

org.apache.uima:uimaj-core

maven
Затронутые версииВерсия исправления

>= 3.0.0-alpha, <= 3.0.0-alpha02

3.0.0-beta

Наименование

org.apache.uima:uimaj-as-core

maven
Затронутые версииВерсия исправления

< 2.10.2

2.10.2

EPSS

Процентиль: 76%
0.00976
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.

CVSS3: 8.8
redhat
почти 8 лет назад

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.

CVSS3: 6.5
nvd
почти 8 лет назад

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.

CVSS3: 6.5
debian
почти 8 лет назад

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0 ...

EPSS

Процентиль: 76%
0.00976
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611