CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:opennlp:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:opennlp:1.8.1:*:*:*:*:*:*:*

History

21 Nov 2024, 03:09

Type Values Removed Values Added
References () http://opennlp.apache.org/news/cve-2017-12620.html - Exploit, Vendor Advisory () http://opennlp.apache.org/news/cve-2017-12620.html - Exploit, Vendor Advisory

Information

Published : 2017-10-03 01:29

Updated : 2024-11-21 03:09


NVD link : CVE-2017-12620

Mitre link : CVE-2017-12620

CVE.ORG link : CVE-2017-12620


JSON object : View

Products Affected

apache

  • opennlp
CWE
CWE-611

Improper Restriction of XML External Entity Reference