Lucene search

K
osvGoogleOSV:GHSA-4C32-XMGJ-2G98
HistoryOct 17, 2018 - 6:22 p.m.

High severity vulnerability that affects org.apache.pdfbox:pdfbox

2018-10-1718:22:15
Google
osv.dev
9

0.001 Low

EPSS

Percentile

39.2%

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.