CVE-2019-5312
Summary
| CVE | CVE-2019-5312 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-04 16:29:00 UTC |
| Updated | 2019-01-16 18:20:00 UTC |
| Description | An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| XXE Vulnerability · Issue #903 · Wechat-Group/WxJava · GitHub |
MISC |
github.com |
Exploit, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996953 Java (Maven) Security Update for com.github.binarywang:weixin-java-common (GHSA-h755-h99p-9ffv)