GHSA-7j4h-8wpf-rqfh

Suggest an improvement
Source
https://github.com/advisories/GHSA-7j4h-8wpf-rqfh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7j4h-8wpf-rqfh/GHSA-7j4h-8wpf-rqfh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7j4h-8wpf-rqfh
Aliases
  • CVE-2013-4002
Published
2022-05-13T01:01:06Z
Modified
2024-12-03T06:18:52.393319Z
Summary
Missing XML Validation in Apache Xerces2
Details

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.

Database specific
{
    "nvd_published_at": "2013-07-23T11:03:00Z",
    "cwe_ids": [
        "CWE-112"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-08T19:14:49Z"
}
References

Affected packages

Maven / xerces:xercesImpl

Package

Name
xerces:xercesImpl
View open source insights on deps.dev
Purl
pkg:maven/xerces/xercesImpl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.0

Affected versions

2.*

2.0.0
2.0.2
2.2.1
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.2-jaxb-1.0.6
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.10.0
2.11.0