PT-2024-22312 · Apache+2 · Apache Xml Graphics+2
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache XML Graphics FOP version 2.9
Description
The issue is related to an Improper Restriction of XML External Entity Reference, also known as an XXE vulnerability, in Apache XML Graphics FOP. This vulnerability is due to the improper restriction of XML External Entity references.
Recommendations
For Apache XML Graphics FOP version 2.9, upgrade to version 2.10, which fixes the issue.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Xml Graphics
Debian
Suse