Lucene search

K
osvGoogleOSV:GHSA-MH83-JCW5-RJH8
HistoryJan 14, 2022 - 9:07 p.m.

XML External Entity Reference in edu.stanford.nlp:stanford-corenlp

2022-01-1421:07:23
Google
osv.dev
10
transformxml
saxparser
saxparserfactory
feature_secure_processing
xxe attacks
edu.stanford.nlp

EPSS

0.001

Percentile

33.4%

The TransformXML() function makes use of SAXParser generated from a SAXParserFactory with no FEATURE_SECURE_PROCESSING set, allowing for XXE attacks.

EPSS

0.001

Percentile

33.4%

Related for OSV:GHSA-MH83-JCW5-RJH8