XML injection (XXE) In org.apache.poi:poi
Description
Improper Restriction of XML External Entity Reference in Apache POI The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.10.1 | ||
debian 13 | 3.10.1-1 | ||
debian 14 | 3.10.1-1 | ||
debian 12 | 3.10.1-1 | ||
debian 11 | 3.10.1-1 | ||
maven | 3.10.1, 3.11-beta2 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15.