PT-2018-9485 · Dom4J+3 · Dom4J+3
CVE-2018-1000632
·
Publicado
2018-07-01
·
Atualizado
2026-06-17
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
dom4j versions prior to 2.1.1
Description
The issue is related to an XML Injection vulnerability in the Class: Element, specifically in the
addElement and addAttribute methods. This can result in an attacker tampering with XML documents through XML injection, which appears to be exploitable via an attacker specifying attributes or elements in the XML document.Recommendations
For dom4j versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
addElement and addAttribute methods in the Element class until a patch is available.
Restrict access to the vulnerable Class: Element to minimize the risk of exploitation.
Avoid using the addElement and addAttribute methods in the affected XML documents until the issue is resolved.Exploit
Correção
DoS
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Os
Suse
Ubuntu
Dom4J