The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-3"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-3"
}
]
}{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-6"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-6"
}
]
}{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-7"
}
]
}{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-7"
}
]
}{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-7"
}
]
}{
"binaries": [
{
"binary_name": "libcastor-anttasks-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-codegen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-core-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-ddlgen-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-jdo-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-java",
"binary_version": "1.3.2-7"
},
{
"binary_name": "libcastor-xml-schema-java",
"binary_version": "1.3.2-7"
}
]
}