Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

Improper Restriction of XML External Entity Reference in Apache OpenNLP

GHSA-h22x-hm8g-rxpg · CVE-2017-12620

Published · Modified

Description

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

Ready to move

Start Securing

Free, no credit card | First findings in minutes