logo

Database

XML injection (XXE) In org.dom4j:dom4j

Description

Withdrawn Advisory: dom4j XML Entity Expansion vulnerability

Withdrawn Advisory

This advisory has been withdrawn because the underlying vulnerability could not be reproduced. This link is maintained to preserve external references.

Original Description

An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version