Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS00angyLWh2cXctOTNqOc4AAxvF

dd-plist XML External Entitly vulnerability

A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to version 1.18 is able to address this issue. The name of the patch is 8c954e8d9f6f6863729e50105a8abf3f87fff74c. It is recommended to upgrade the affected component. VDB-221486 is the identifier assigned to this vulnerability.

Permalink: https://github.com/advisories/GHSA-4jx2-hvqw-93j9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00angyLWh2cXctOTNqOc4AAxvF
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 7 months ago


CVSS Score: 7.8
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-4jx2-hvqw-93j9, CVE-2016-15026
References: Repository: https://github.com/3breadt/dd-plist
Blast Radius: 18.5

Affected Packages

maven:com.googlecode.plist:dd-plist
Dependent packages: 137
Dependent repositories: 236
Downloads:
Affected Version Ranges: < 1.18
Fixed in: 1.18
All affected versions:
All unaffected versions: