Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqdjYtZ3E3Ny0zbWp3
XXE attack in Mapfish Print
Impact
A user can do to an XML External Entity (XXE) attack with the provided SDL style.
Patches
Use version >= 3.24
Workarounds
No
References
- https://cwe.mitre.org/data/definitions/611.html
- https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e
For more information
If you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397
Permalink: https://github.com/advisories/GHSA-vjv6-gq77-3mjwJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqdjYtZ3E3Ny0zbWp3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 4 years ago
Updated: 10 months ago
CVSS Score: 9.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Identifiers: GHSA-vjv6-gq77-3mjw, CVE-2020-15232
References:
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-vjv6-gq77-3mjw
- https://github.com/mapfish/mapfish-print/pull/1397
- https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e
- https://nvd.nist.gov/vuln/detail/CVE-2020-15232
- https://github.com/advisories/GHSA-vjv6-gq77-3mjw
Blast Radius: 17.7
Affected Packages
maven:org.mapfish.print:print-standalone
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5
maven:org.mapfish.print:print-servlet
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5
maven:org.mapfish.print:print-lib
Dependent packages: 0Dependent repositories: 80
Downloads:
Affected Version Ranges: >= 3.0, < 3.24
Fixed in: 3.24
All affected versions: 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.10.1, 3.10.2, 3.10.3, 3.10.4, 3.10.5, 3.10.6, 3.10.7, 3.10.8, 3.11.0, 3.11.1, 3.11.2, 3.11.3, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.18.4, 3.19.0, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.22.0
All unaffected versions: 1.2.0, 2.0.0, 2.1.0, 2.1.2, 2.1.3, 2.1.4, 2.1.5