CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:xerces:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:xerces:2.12.0:sp1:*:*:*:*:*:*
cpe:2.3:a:redhat:xerces:2.12.0:sp2:*:*:*:*:*:*

History

21 Nov 2024, 05:03

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1860054 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1860054 - Issue Tracking, Vendor Advisory
References () https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E - () https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E -

07 Nov 2023, 03:17

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103@%3Cj-users.xerces.apache.org%3E', 'name': '[xerces-j-users] 20201014 Security vulnerability in 2.12.0', 'tags': [], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E -

Information

Published : 2020-09-17 15:15

Updated : 2024-11-21 05:03


NVD link : CVE-2020-14338

Mitre link : CVE-2020-14338

CVE.ORG link : CVE-2020-14338


JSON object : View

Products Affected

redhat

  • xerces
CWE
CWE-20

Improper Input Validation