PT-2017-12606 · Apache · Apache Xerces-C+1
CVE-2017-12621
·
Publicado
2017-09-27
·
Atualizado
2023-02-09
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Commons Jelly versions prior to 1.0.1
Description
The issue arises during Jelly (xml) file parsing with Apache Xerces. If a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, the parser will attempt to connect to the specified URL during parser instantiation. This could lead to XML External Entity (XXE) attacks.
Recommendations
For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of custom doctype entities with "SYSTEM" entities to minimize the risk of exploitation.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Commons Jelly
Apache Xerces-C