logo

Database

XML injection (XXE) In org.jdom:jdom2

Description

XML External Entity (XXE) Injection in JDOM An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. As a workaround, to avoid external entities being expanded, one can call builder.setExpandEntities(false) and they won't be expanded.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

1-10 of 13

10

References

1. https://github.com/hunterhacker/jdom/issues/1892. https://github.com/hunterhacker/jdom/pull/1883. https://github.com/hunterhacker/jdom/commit/dd4f3c2fc7893edd914954c73eb577f925a7d3614. https://www.oracle.com/security-alerts/cpujul2022.html5. https://www.oracle.com/security-alerts/cpuapr2022.html6. https://lists.fedoraproject.org/archives/list/[email protected]/message/EWFVYTHGILOQXUA7U3SPOERQXL7OPSZG7. https://lists.fedoraproject.org/archives/list/[email protected]/message/AH46QHE5GIMT6BL6C3GDTOYF27JYILXM8. https://lists.apache.org/thread.html/rfb7a93e40ebeb1e0068cde0bf3834dcab46bb1ef06d6424db48ed9fd@%3Cdev.tika.apache.org%3E9. https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f@%3Cissues.solr.apache.org%3E10. https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6@%3Cissues.solr.apache.org%3E11. https://lists.apache.org/thread.html/r89b3800cfabb1e773e49425e5d4239c28a659839a2eca6af3431482e@%3Cissues.solr.apache.org%3E12. https://lists.apache.org/thread.html/r845e987b7cd8efe610284958e997b84583f5a98d3394adc09e3482fe@%3Cissues.solr.apache.org%3E13. https://lists.apache.org/thread.html/r6db397ae7281ead825338200d1f62d2827585a70797cc9ac0c4bd23f@%3Cissues.solr.apache.org%3E14. https://lists.apache.org/thread.html/r5674106135bb1a6ef57483f4c63a9c44bca85d0e2a8a05895a8f1d89@%3Cissues.solr.apache.org%3E15. https://lists.apache.org/thread.html/r21c406c7ed88fe340db7dbae75e58355159e6c324037c7d5547bf40b@%3Cissues.solr.apache.org%3E16. https://github.com/hunterhacker/jdom/releases/tag/JDOM-2.0.6.117. https://github.com/hunterhacker/jdom/releases18. https://alephsecurity.com/vulns/aleph-2021003