CVE-2019-9843
Summary
| CVE | CVE-2019-9843 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-28 18:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-9843: The XML parser isn't respecting resolveExternalEntities as false · Issue #358 · diffplug/spotless · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| spotless/CHANGES.md at master · diffplug/spotless · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| spotless/CHANGES.md at master · diffplug/spotless · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| Pony Mail! | lists.apache.org | ||
| WTP - Ignore external URIs by default by fvgh · Pull Request #369 · diffplug/spotless · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982016 Java (maven) Security Update for com.diffplug.spotless:spotless-plugin-maven (GHSA-7v35-qwwj-p98g)