PT-2017-12606 · Apache · Apache Xerces-C+1

CVE-2017-12621

·

Publicado

2017-09-27

·

Atualizado

2023-02-09

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Commons Jelly versions prior to 1.0.1
Description The issue arises during Jelly (xml) file parsing with Apache Xerces. If a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, the parser will attempt to connect to the specified URL during parser instantiation. This could lead to XML External Entity (XXE) attacks.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of custom doctype entities with "SYSTEM" entities to minimize the risk of exploitation.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12621
GHSA-6G33-82GC-3PW5

Produtos afetados

Apache Commons Jelly
Apache Xerces-C