Lucene search

K
osvGoogleOSV:GHSA-PMQQ-7WFV-JFFF
HistoryMay 13, 2022 - 1:14 a.m.

Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability

2022-05-1301:14:25
Google
osv.dev
34

5.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

5.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%