Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10782

Опубликовано: 27 янв. 2020
Источник: redhat
CVSS3: 5.3

Описание

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.

Отчет

No Red Hat products use the vulnerable code affected by this flaw. However, Red Hat Fuse 7 does provide it in its offline maven repository, and as such is affected at a low impact. This may be resolved in a future release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7checkstyleFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1796858checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.

CVSS3: 5.3
nvd
около 6 лет назад

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.

CVSS3: 5.3
debian
около 6 лет назад

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulner ...

CVSS3: 5.3
github
около 6 лет назад

XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))

5.3 Medium

CVSS3