Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 Maven

Improper Restriction of Recursive Entity References in DTDs in Apache POI

GHSA-78vv-qj73-h9m5 · CVE-2017-5644

Published · Modified

Description

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Ready to move

Start Securing

Free, no credit card | First findings in minutes