CVE-2020-10683
🟠 Łataj w tym tygodniu
Dom4j umożliwia ataki XXE poprzez domyślne włączenie zewnętrznych DTD i encji.
CVSS
9.8
EPSS
7.3%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
xxe
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 7.3% |
| Opublikowano (NVD) | 2020-05-01 19:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-25 16:28:27 UTC |
Referencje
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html (cve@mitre.org) [Third Party Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=1694235 (cve@mitre.org) [Issue Tracking, Patch, Third Party Advisory]
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html (cve@mitre.org) [Third Party Advisory]
- https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658 (cve@mitre.org) [Patch, Third Party Advisory]
- https://github.com/dom4j/dom4j/commits/version-2.0.3 (cve@mitre.org) [Patch, Third Party Advisory]
- https://github.com/dom4j/dom4j/issues/87 (cve@mitre.org) [Third Party Advisory]
- https://github.com/dom4j/dom4j/releases/tag/version-2.1.3 (cve@mitre.org) [Release Notes, Third Party Advisory]
- https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E (cve@mitre.org)
- https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E (cve@mitre.org)
- https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E (cve@mitre.org)
- https://security.netapp.com/advisory/ntap-20200518-0002/ (cve@mitre.org) [Third Party Advisory]
- https://usn.ubuntu.com/4575-1/ (cve@mitre.org) [Third Party Advisory]
- https://www.oracle.com//security-alerts/cpujul2021.html (cve@mitre.org) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuApr2021.html (cve@mitre.org) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujan2021.html (cve@mitre.org) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujan2022.html (cve@mitre.org) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2020.html (cve@mitre.org) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html (cve@mitre.org)
- https://www.oracle.com/security-alerts/cpuoct2020.html (cve@mitre.org) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2021.html (cve@mitre.org) [Patch, Third Party Advisory]