Apache PDFBox is vulnerable to XML external entity (XXE) attacks. The XML parser does not disable external DTDs, which would allow an attacker to perform XXE attacks using a malicious XFDF file.
CPE | Name | Operator | Version |
---|---|---|---|
apache pdfbox | eq | 2.0.14 | |
apache pdfbox | eq | 2.0.14 |
mail-archives.apache.org/mod_mbox/www-announce/201904.mbox/%3C1b8bd73c-a3be-9411-113f-0108a6f2966e%40apache.org%3E
lists.apache.org/thread.html/1a3756557f8cb02790b7183ccf7665ae23f608a421c4f723113bca79@%3Cusers.pdfbox.apache.org%3E
lists.apache.org/thread.html/8a19bd6d43e359913341043c2a114f91f9e4ae170059539ad1f5673c@%3Ccommits.tika.apache.org%3E
lists.apache.org/thread.html/bc8db1bf459f1ad909da47350ed554ee745abe9f25f2b50cad4e06dd@%3Cserver-dev.james.apache.org%3E
lists.apache.org/thread.html/be86fcd7cd423a3fe6b73a3cb9d7cac0b619d0deb99e6b5d172c98f4@%3Ccommits.tika.apache.org%3E
lists.apache.org/thread.html/r0a2141abeddae66dd57025f1681c8425834062b7c0c7e0b1d830a95d@%3Cusers.pdfbox.apache.org%3E
lists.apache.org/thread.html/r32b8102392a174b17fd19509a9e76047f74852b77b7bf46af95e45a2@%3Cserver-dev.james.apache.org%3E
lists.fedoraproject.org/archives/list/[email protected]/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/
lists.fedoraproject.org/archives/list/[email protected]/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/
www.oracle.com//security-alerts/cpujul2021.html
www.oracle.com/security-alerts/cpuapr2020.html
www.oracle.com/security-alerts/cpuApr2021.html
www.oracle.com/security-alerts/cpuoct2021.html