CVE-2021-23926
Summary
| CVE | CVE-2021-23926 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-14 15:15:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [XMLBEANS-517] Use safe XML parsers - ASF JIRA |
MISC |
issues.apache.org |
Issue Tracking, Vendor Advisory |
| [axis-java-dev] 20210312 xmlbeans 2.6.0 and CVE-2021-23926 |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Vendor Advisory |
| Oracle Critical Patch Update Advisory - October 2021 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Vendor Advisory |
| CVE-2021-23926 Apache XMLBeans Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [axis-java-dev] 20210312 Re: xmlbeans 2.6.0 and CVE-2021-23926 |
|
lists.apache.org |
|
| [SECURITY] [DLA 2693-1] xmlbeans security update |
MLIST |
lists.debian.org |
|
| Index of / |
MISC |
poi.apache.org |
Product, Vendor Advisory |
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178686 Debian Security Update for xmlbeans (DLA 2693-1)
- 179604 Debian Security Update for xmlbeans (CVE-2021-23926)
- 375970 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUOCT2021)
- 752763 SUSE Enterprise Linux Security Update for xmlbeans (SUSE-SU-2022:3875-1)
- 752765 SUSE Enterprise Linux Security Update for xmlbeans (SUSE-SU-2022:3876-1)
- 980332 Java (maven) Security Update for org.apache.xmlbeans:xmlbeans (GHSA-mw3r-pfmg-xp92)