Lucene search

K
osvGoogleOSV:GHSA-C9JJ-3WVG-Q65H
HistoryJul 05, 2019 - 9:12 p.m.

Vulnerability that affects org.apache.pdfbox:pdfbox

2019-07-0521:12:54
Google
osv.dev
10

EPSS

0.006

Percentile

79.3%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

References