← Retour aux CVEs
CVE-2020-10683
CRITICAL9.8
Description
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie5/1/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
canonical:ubuntu_linuxdom4j_project:dom4jnetapp:oncommand_api_servicesnetapp:oncommand_workflow_automationnetapp:snap_creator_frameworknetapp:snapcenternetapp:snapmanageropensuse:leaporacle:agile_plmoracle:application_testing_suiteoracle:banking_platformoracle:business_process_management_suiteoracle:communications_application_session_controlleroracle:communications_diameter_signaling_routeroracle:communications_unified_inventory_managementoracle:data_integratororacle:documakeroracle:endeca_information_discovery_integratororacle:enterprise_data_qualityoracle:enterprise_manager_base_platformoracle:financial_services_analytical_applications_infrastructureoracle:flexcube_core_bankingoracle:fusion_middlewareoracle:health_sciences_empirica_signaloracle:health_sciences_information_manageroracle:insurance_policy_administration_j2eeoracle:insurance_rules_paletteoracle:jdeveloperoracle:primavera_p6_enterprise_project_portfolio_managementoracle:rapid_planningoracle:retail_customer_management_and_segmentation_foundationoracle:retail_integration_busoracle:retail_order_brokeroracle:retail_price_managementoracle:retail_xstore_point_of_serviceoracle:storagetek_tape_analytics_sw_tooloracle:utilities_frameworkoracle:webcenter_portal
Faiblesses (CWE)
CWE-611
References
https://bugzilla.redhat.com/show_bug.cgi?id=1694235(cve@mitre.org)
https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html(cve@mitre.org)
https://github.com/dom4j/dom4j/commits/version-2.0.3(cve@mitre.org)
https://github.com/dom4j/dom4j/issues/87(cve@mitre.org)
https://github.com/dom4j/dom4j/releases/tag/version-2.1.3(cve@mitre.org)
https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E(cve@mitre.org)
https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E(cve@mitre.org)
https://security.netapp.com/advisory/ntap-20200518-0002/(cve@mitre.org)
https://usn.ubuntu.com/4575-1/(cve@mitre.org)
https://www.oracle.com//security-alerts/cpujul2021.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpuApr2021.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpujan2021.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpujan2022.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpujul2020.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpujul2022.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpuoct2020.html(cve@mitre.org)
https://www.oracle.com/security-alerts/cpuoct2021.html(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=1694235(af854a3a-2127-422b-91ae-364da2661108)
https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/dom4j/dom4j/commits/version-2.0.3(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/dom4j/dom4j/issues/87(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/dom4j/dom4j/releases/tag/version-2.1.3(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20200518-0002/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4575-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com//security-alerts/cpujul2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuApr2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujul2020.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujul2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuoct2020.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuoct2021.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.