logo

CVE-2017-12620 org.apache.opennlp:opennlp-tools

Package

Manager: maven
Name: org.apache.opennlp:opennlp-tools
Vulnerable Version: >=1.5.0 <1.8.2

Severity

Level: Critical

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.01018 pctl0.76346

Details

Improper Restriction of XML External Entity Reference in Apache OpenNLP When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

Metadata

Created: 2022-05-17T00:29:00Z
Modified: 2022-07-01T20:36:40Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h22x-hm8g-rxpg/GHSA-h22x-hm8g-rxpg.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-h22x-hm8g-rxpg
Finding: F083
Auto approve: 1