Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-45960

Опубликовано: 25 окт. 2023
Источник: redhat
CVSS3: 0

Описание

An issue was found in org.dom4j that may allow a remote attacker to obtain sensitive information via the setFeature function. This CVE is currently disputed by the maintainers.

Отчет

This CVE was reported to Mitre via a third party in a discussion in their Github page and not from the maintainers of the org.dom4j package. They do not consider this a CVE on dom4j, as this may depend on how you are using setFeature methods and the underlying parser, which may be different from one scenario to another. For this reason, there is a reference in the External References section explaining that this CVE is currently being disputed. Therefore, the CVSS and Impact are 0 and None, respectively.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2dom4jNot affected
Migration Toolkit for Applications 6dom4jNot affected
Migration Toolkit for Runtimesdom4jNot affected
Red Hat AMQ Broker 7dom4jNot affected
Red Hat Data Grid 8dom4jNot affected
Red Hat Decision Manager 7dom4jNot affected
Red Hat Fuse 7dom4jNot affected
Red Hat Integration Camel K 1dom4jNot affected
Red Hat JBoss Data Grid 7dom4jNot affected
Red Hat JBoss Enterprise Application Platform 6dom4jNot affected

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=2246435dom4j: XML External Entity on SAXReader

0 Low

CVSS3

Связанные уязвимости

ubuntu
больше 2 лет назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

nvd
больше 2 лет назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

github
больше 2 лет назад

Withdrawn Advisory: dom4j XML Entity Expansion vulnerability

0 Low

CVSS3