org.apache.pdfbox:preflight-app@2.0.0-RC3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.pdfbox:preflight-app package. This does not include vulnerabilities belonging to this package’s dependencies.

XML External Entity (XXE) Injection

org.apache.pdfbox:preflight-app Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

[1.8.0,1.8.11] [2.0.0,2.0.1)