GHSA-wvpv-8524-wg6x

Suggest an improvement
Source
https://github.com/advisories/GHSA-wvpv-8524-wg6x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wvpv-8524-wg6x/GHSA-wvpv-8524-wg6x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wvpv-8524-wg6x
Aliases
Published
2022-05-14T03:38:59Z
Modified
2023-11-08T03:59:15Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
mxGraph vulnerable to XXE attacks
Details

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

Database specific
{
    "cwe_ids":  [
        "CWE-611"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-10-19T19:08:39Z",
    "nvd_published_at":  "2018-02-24T02:29:00Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / mxgraph

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.7.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wvpv-8524-wg6x/GHSA-wvpv-8524-wg6x.json"