XML injection (XXE) In cn.hutool:hutool-core
Description
HuTool XML parsing module has blind XXE vulnerability A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 5.8.20 |
Aliases
1. 2. 3. 4.
References
1.