CRITICAL 9.8 Maven
Improper Restriction of XML External Entity Reference in MPXJ
GHSA-wcp5-m52f-mhh5 · CVE-2020-25020
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
"MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components."
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-25020
- WEB https://github.com/joniles/mpxj/pull/178/commits/c3e457f7a16facfe563eade82b0fa8736a8c96f9
- PACKAGE https://github.com/joniles/mpxj
- WEB https://github.com/joniles/mpxj/releases/tag/v8.1.4
- WEB https://www.oracle.com/security-alerts/cpujan2021.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes