XML injection (XXE) In org.apache.poi:poi
Description
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.14 | ||
debian 12 | - | ||
debian 11 | - | ||
debian 13 | - | ||
maven | 3.14 | ||
debian 14 | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.