CVE-2023-45960
Summary
| CVE | CVE-2023-45960 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-25 18:17:00 UTC |
| Updated | 2023-11-07 04:21:00 UTC |
| Description | ** DISPUTED ** An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function. NOTE: the vendor and original reporter indicate that this is not a vulnerability because setFeature only sets features, which "can be safe in one case and unsafe in another." |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Dom4j Project |
Dom4j |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| works only up to v2.1.0 · Issue #1 · joker-xiaoyan/XXE-SAXReader · GitHub |
MISC |
github.com |
|
| GitHub - joker-xiaoyan/XXE-SAXReader |
MISC |
github.com |
|
| according to some vulnerability databases, dom4j is affected by CVE-2023-45960 · Issue #171 · dom4j/dom4j · GitHub |
MISC |
github.com |
|
| dom4j |
MISC |
dom4j.github.io |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995759 Java (Maven) Security Update for org.dom4j:dom4j (GHSA-fgq9-fc3q-vqmw)