Lucene search

K
osvGoogleOSV:GHSA-7RP6-W7MG-H8RW
HistorySep 20, 2021 - 8:22 p.m.

XML External Entity Reference in Apache Jena

2021-09-2020:22:05
Google
osv.dev
21
apache jena
xml processing
vulnerability
xxe
local files
remote server
software

EPSS

0.003

Percentile

70.9%

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

EPSS

0.003

Percentile

70.9%