org.apache.cayenne.modeler:cayenne-modeler@4.0.RC1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.cayenne.modeler:cayenne-modeler package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
XML External Entity (XXE) Injection

org.apache.cayenne.modeler:cayenne-modeler is a desktop GUI tool for working with Cayenne ORM models stored as XML files.

Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. If an attacker tricks a user into opening a malicious XML file, they were able to instruct the XML parser to transfer files from a local machine to a remote machine controlled by the attacker.

How to fix XML External Entity (XXE) Injection?

Upgrade org.apache.cayenne.modeler:cayenne-modeler to versions 3.1.3, 4.0, 4.1.M2 or higher.

[4.0.B1,4.0) [4.1.M1,4.1.M2)