Lucene search

K
cvelistApacheCVELIST:CVE-2019-0228
HistoryApr 17, 2019 - 2:07 p.m.

CVE-2019-0228

2019-04-1714:07:34
apache
www.cve.org
2

9.1 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

CNA Affected

[
  {
    "product": "Apache PDFBox",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Apache PDFBox 2.0.14"
      }
    ]
  }
]

References

9.1 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%