OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2024-10-05-3.0.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6c50e89"
}
]
}
]
[
{
"deprecated": false,
"id": "CVE-2024-58335-8b7c9ce3",
"target": {
"file": "src/main/java/org/oxt/toolbox/visualization/VisualizerImpl.java",
"function": "xsltTransformationFromStringWriter"
},
"digest": {
"function_hash": "135909173686231881855504909569538957878",
"length": 557.0
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/jcthiele/openxrechnungtoolbox/commit/6c50e8979924b09f336c976cbad3a9ebfe25ebf9"
},
{
"deprecated": false,
"id": "CVE-2024-58335-f70f3549",
"target": {
"file": "src/main/java/org/oxt/toolbox/visualization/VisualizerImpl.java"
},
"digest": {
"line_hashes": [
"9432205948509338417827718264121970748",
"124127463788678294553700431816112564725",
"238114869201622947979670670152317924232",
"169317099862735224096945059384580184108",
"13651817299829584518405290267341685011",
"201992976830863104942285700442950842948",
"66213062299927042290783232880627834705",
"186211273429314880795922747392516243740",
"272387255340619825255196243675669910089",
"307335764006965151638752718621354950308",
"294544188066198699689729227135813529989",
"18647826803584612515082456354978722861",
"222423373171099673302632883197955776963",
"78248550583327622458870526680891929645",
"19556189292209570462442653570741178863",
"96010537811942127021765088113039058396"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/jcthiele/openxrechnungtoolbox/commit/6c50e8979924b09f336c976cbad3a9ebfe25ebf9"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58335.json"