Описание
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, cyclonedx-core-java leverages XPath expressions to determine the schema version of the BOM. The DocumentBuilderFactory used to evaluate XPath expressions was not configured securely, making the library vulnerable to XML External Entity (XXE) injection. This vulnerability has been fixed in cyclonedx-core-java version 9.0.4.
A flaw was found in cyclonedx-core-java. It is vulnerable to XML External Entity (XXE) injection due to an insecure configuration of the DocumentBuilderFactory used to evaluate XPath expressions.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Applications 6 | cyclonedx-core-java | Will not fix | ||
| Migration Toolkit for Runtimes | cyclonedx-core-java | Will not fix | ||
| Red Hat build of Apache Camel for Spring Boot 4 | cyclonedx-core-java | Not affected | ||
| Red Hat build of Quarkus | cyclonedx-core-java | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | cyclonedx-core-java | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | cyclonedx-core-java | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cyclonedx-core-java | Not affected | ||
| streams for Apache Kafka | cyclonedx-core-java | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The `DocumentBuilderFactory` used to evaluate XPath expressions was not configured securely, making the library vulnerable to XML External Entity (XXE) injection. This vulnerability has been fixed in cyclonedx-core-java version 9.0.4.
Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
EPSS
7.5 High
CVSS3