Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZwY2MtM3JmeC00Z3Bt

Dom4j contains a XML Injection vulnerability

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Note: This advisory applies to dom4j:dom4j version 1.x legacy artifacts. To resolve this a change to the latest version of org.dom4j:dom4j is recommended.

Permalink: https://github.com/advisories/GHSA-6pcc-3rfx-4gpm
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZwY2MtM3JmeC00Z3Bt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: over 1 year ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Identifiers: GHSA-6pcc-3rfx-4gpm, CVE-2018-1000632
References: Repository: https://github.com/dom4j/dom4j
Blast Radius: 33.5

Affected Packages

maven:dom4j:dom4j
Dependent packages: 1,969
Dependent repositories: 29,699
Downloads:
Affected Version Ranges: <= 1.6.1
No known fixed version
All affected versions: 1.5.1, 1.5.2, 1.6.1
maven:org.dom4j:dom4j
Dependent packages: 1,037
Dependent repositories: 4,336
Downloads:
Affected Version Ranges: = 2.1.0, < 2.0.3
Fixed in: 2.1.1, 2.0.3
All affected versions: 2.0.0, 2.0.1, 2.0.2, 2.1.0
All unaffected versions: 2.0.3, 2.1.1, 2.1.3, 2.1.4