Логотип exploitDog
bind:CVE-2019-9843
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-9843

Количество 2

Количество 2

nvd логотип

CVE-2019-9843

больше 6 лет назад

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7v35-qwwj-p98g

больше 6 лет назад

Improper Restriction of XML External Entity Reference in DiffPlug Spotless

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-9843

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-7v35-qwwj-p98g

Improper Restriction of XML External Entity Reference in DiffPlug Spotless

CVSS3: 7.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу