Lucene search

K
redhatcveRedhat.comRH:CVE-2019-12415
HistoryFeb 13, 2020 - 11:44 a.m.

CVE-2019-12415

2020-02-1311:44:58
redhat.com
access.redhat.com
30

0.001 Low

EPSS

Percentile

40.7%

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Mitigation

The vulnerability is in the XSSFExportToXml util; avoid usage of this tool to mitigate the vulnerability.