CVE-2017-12620 – org.apache.opennlp:opennlp-tools
Package
Manager: maven
Name: org.apache.opennlp:opennlp-tools
Vulnerable Version: >=1.5.0 <1.8.2
Severity
Level: Critical
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.01018 pctl0.76346
Details
Improper Restriction of XML External Entity Reference in Apache OpenNLP When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
Metadata
Created: 2022-05-17T00:29:00Z
Modified: 2022-07-01T20:36:40Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h22x-hm8g-rxpg/GHSA-h22x-hm8g-rxpg.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-h22x-hm8g-rxpg
Finding: F083
Auto approve: 1