CVE-2019-10782

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Configurations

Configuration 1 (hide)

cpe:2.3:a:checkstyle:checkstyle:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:19

Type Values Removed Values Added
References () https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E - () https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E -
References () https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html - () https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html -
References () https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266 - Exploit, Third Party Advisory () https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266 - Exploit, Third Party Advisory

07 Nov 2023, 03:02

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3E', 'name': '[nifi-commits] 20200421 svn commit: r1876802 - /nifi/site/trunk/registry-security.html', 'tags': [], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E -

Information

Published : 2020-01-30 23:15

Updated : 2024-11-21 04:19


NVD link : CVE-2019-10782

Mitre link : CVE-2019-10782

CVE.ORG link : CVE-2019-10782


JSON object : View

Products Affected

checkstyle

  • checkstyle
CWE
CWE-611

Improper Restriction of XML External Entity Reference