logo

Database

XML injection (XXE) In org.apache.pdfbox:pdfbox

Description

High severity vulnerability that affects org.apache.pdfbox:pdfbox Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions