Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqdjYtZ3E3Ny0zbWp3

XXE attack in Mapfish Print

Impact

A user can do to an XML External Entity (XXE) attack with the provided SDL style.

Patches

Use version >= 3.24

Workarounds

No

References

For more information

If you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397

Permalink: https://github.com/advisories/GHSA-vjv6-gq77-3mjw
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqdjYtZ3E3Ny0zbWp3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 4 years ago
Updated: 10 months ago


CVSS Score: 9.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Identifiers: GHSA-vjv6-gq77-3mjw, CVE-2020-15232
References: Repository: https://github.com/mapfish/mapfish-print
Blast Radius: 17.7

Affected Packages

maven:org.mapfish.print:print-standalone
Dependent packages: 0
Dependent repositories: 1
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5
maven:org.mapfish.print:print-servlet
Dependent packages: 0
Dependent repositories: 1
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5
maven:org.mapfish.print:print-lib
Dependent packages: 0
Dependent repositories: 80
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5