All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
References
Configurations
History
21 Nov 2024, 04:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E - | |
References | () https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html - | |
References | () https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266 - Exploit, Third Party Advisory |
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-01-30 23:15
Updated : 2024-11-21 04:19
NVD link : CVE-2019-10782
Mitre link : CVE-2019-10782
CVE.ORG link : CVE-2019-10782
JSON object : View
Products Affected
checkstyle
- checkstyle
CWE
CWE-611
Improper Restriction of XML External Entity Reference