In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12415.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.5.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.1.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.2.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.3.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.5.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.0.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.3.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.4.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.3.0.0"
}
]
},
{
"events": [
{
"introduced": "8.0.6"
},
{
"last_affected": "8.0.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.2.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.2.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.57"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.59"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.12.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.8.8.1"
}
]
},
{
"events": [
{
"introduced": "17.7"
},
{
"last_affected": "17.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
}
]