GHSA-w3gh-g32m-cvhr

Suggest an improvement
Source
https://github.com/advisories/GHSA-w3gh-g32m-cvhr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-w3gh-g32m-cvhr/GHSA-w3gh-g32m-cvhr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w3gh-g32m-cvhr
Aliases
Published
2018-10-18T16:56:47Z
Modified
2024-12-02T05:42:14.034968Z
Summary
High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3
Details

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.

Database specific
{
    "nvd_published_at": "2018-07-05T13:29:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:59:21Z"
}
References

Affected packages

Maven / org.apache.cxf.fediz:fediz-spring

Package

Name
org.apache.cxf.fediz:fediz-spring
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.fediz/fediz-spring

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4

Affected versions

1.*

1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3

Maven / org.apache.cxf.fediz:fediz-spring2

Package

Name
org.apache.cxf.fediz:fediz-spring2
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.fediz/fediz-spring2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4

Affected versions

1.*

1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3

Maven / org.apache.cxf.fediz:fediz-spring3

Package

Name
org.apache.cxf.fediz:fediz-spring3
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.fediz/fediz-spring3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4

Affected versions

1.*

1.4.0
1.4.1
1.4.2
1.4.3

Maven / org.apache.cxf.fediz:fediz-jetty8

Package

Name
org.apache.cxf.fediz:fediz-jetty8
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.fediz/fediz-jetty8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4

Affected versions

1.*

1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3

Maven / org.apache.cxf.fediz:fediz-jetty9

Package

Name
org.apache.cxf.fediz:fediz-jetty9
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.fediz/fediz-jetty9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4

Affected versions

1.*

1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3