corenlp is vulnerable to Improper Restriction of XML External Entity Reference
[
{
"id": "CVE-2022-0239-8437e4b5",
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "getValidatingXmlParser",
"file": "src/edu/stanford/nlp/util/XMLUtils.java"
},
"digest": {
"length": 831.0,
"function_hash": "100764702940495631814522020455600243301"
},
"signature_type": "Function"
},
{
"id": "CVE-2022-0239-a980c3ad",
"source": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/edu/stanford/nlp/util/XMLUtils.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"238565169868112149853538462787840540943",
"218625043191496645806240340423629875787",
"79570439888172606774987602873821909791",
"241063994109605614212165091553513739617"
]
},
"signature_type": "Line"
}
]