XML External Entity (XXE) Injection Affecting com.fasterxml.woodstox:woodstox-core package, versions [,5.3.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-COMFASTERXMLWOODSTOX-2928754
- published 16 Jun 2022
- disclosed 16 Jun 2022
- credit Unknown
How to fix?
Upgrade com.fasterxml.woodstox:woodstox-core
to version 5.3.0 or higher.
Overview
com.fasterxml.woodstox:woodstox-core is a None
Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. due to insecure processing and missing restriction of XML files. An attacker can exploit this vulnerability by sending a specially crafted malicious XML file that contains XML entities with URIs that resolve to documents outside of the intended sphere of control.
References
CVSS Scores
version 3.1