Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 Maven

XML External Entity Reference in edu.stanford.nlp:stanford-corenlp

GHSA-mh83-jcw5-rjh8 · CVE-2022-0198

Published · Modified

Description

The TransformXML() function makes use of SAXParser generated from a SAXParserFactory with no FEATURE_SECURE_PROCESSING set, allowing for XXE attacks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes