2.5.11
15 years ago
26 days ago
Known vulnerabilities in the org.apache.opennlp:opennlp-tools package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.opennlp:opennlp-tools is an is a machine learning based toolkit for the processing of natural language text. Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value in the Note: This is only exploitable if the application loads model files from untrusted or semi-trusted sources. How to fix Memory Allocation with Excessive Size Value? Upgrade | [,2.5.9)[3.0.0-M1,3.0.0-M3) |
org.apache.opennlp:opennlp-tools is an is a machine learning based toolkit for the processing of natural language text. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection via the How to fix XML External Entity (XXE) Injection? Upgrade | [,2.5.9) |
org.apache.opennlp:opennlp-tools is an is a machine learning based toolkit for the processing of natural language text. Affected versions of this package are vulnerable to Unsafe Reflection that leads to arbitrary class instantiation, via the This is only exploitable if a class with attacker-controlled side effects in its static initializer or no-argument constructor is present on the classpath, and the attacker is able to supply a model archive from an untrusted source, such as a shared Hugging Face model. Note: The fix for this vulnerability involves an allowlist approach, a consequence of which is that classes under the How to fix Unsafe Reflection? Upgrade | [,2.5.9) |
org.apache.opennlp:opennlp-tools is an is a machine learning based toolkit for the processing of natural language text. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. It is possible to perform an XXE attack when loading models or dictionaries from untrusted sources that contain XML. When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected. How to fix XML External Entity (XXE) Injection? Upgrade | [1.5.1-incubating,1.8.2) |